Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.523 exploits
Referência
CVE-2011-0961
Cross-site scripting (XSS) vulnerability in cwhp/device.center.do in the Help servlet in Cisco CiscoWorks Common Service
23RIESGO
abrir ↗Referência
CVE-2018-5759
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
Total Video Player 1.31 - 'DefaultSkin.ini' Local Stack Overflow
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RIESGO
abrir ↗Referência
CVE-2010-2549
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Vista SP1 and SP2 and Server 2008 Gold and
23RIESGO
abrir ↗Referência✓ VexDay Proof
FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote
23RIESGO
abrir ↗Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir ↗Referência
CVE-2016-1803
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir ↗Referência
CVE-2019-15092
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in
23RIESGO
abrir ↗Referência
CVE-2019-25699
Newsbull Haber Script 1.0.0 Authenticated SQL Injection via search parameter
41RIESGO
abrir ↗Referência✓ VexDay Proof
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1)
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP PORTAL - Remote Database Disclosure
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attacker
23RIESGO
abrir ↗Referência
CVE-2022-36551
A Server Side Request Forgery (SSRF) in the Data Import module in Heartex - Label Studio Community Edition versions 1.5.
23RIESGO
abrir ↗Referência
CVE-2015-5889
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RIESGO
abrir ↗Referência
CVE-2016-3989
The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME
23RIESGO
abrir ↗Referência
CVE-2017-3629
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir ↗Referência
CVE-2017-3629
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir ↗Referência
CVE-2020-25901
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we
23RIESGO
abrir ↗Referência
CVE-2012-5452
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Referência
CVE-2012-5452
Multiple cross-site scripting (XSS) vulnerabilities in Subrion CMS 2.2.1 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Referência
CVE-2014-8596
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL c
23RIESGO
abrir ↗Referência
CVE-2017-18344
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly
23RIESGO
abrir ↗Referência
CVE-2015-4062
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remo
38RIESGO
abrir ↗Referência
CVE-2017-7462
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI scr
28RIESGO
abrir ↗Referência
CVE-2015-4062
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remo
38RIESGO
abrir ↗Referência
CVE-2009-3754
Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mx Module Smartor Album FAP 2.0 RC 1 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin/admin_album_otf.php in the MX Smartor Full Album Pack (FAP) 2.0 RC1 mod
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlashBB 1.1.8 - 'sendmsg.php' Remote File Inclusion
PHP remote file inclusion vulnerability in phpbb/sendmsg.php in FlashBB 1.1.8 and earlier allows remote attackers to exe
28RIESGO
abrir ↗Referência✓ VexDay Proof
PHP JOBWEBSITE PRO - 'JobSearch3.php' SQL Injection
SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote att
23RIESGO
abrir ↗Referência
CVE-2013-5092
Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attacke
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.