Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2018-6911
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS
28RIESGO
abrir
ReferênciaVexDay Proof
phpEmployment - 'PHP Upload' Arbitrary File Upload
CVE-2008-6920webappsphp
Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary cod
23RIESGO
abrir
ReferênciaVexDay Proof
Agora 1.4 RC1 - 'MysqlfinderAdmin.php' Remote File Inclusion
CVE-2006-7194webappsphp
PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_glob
23RIESGO
abrir
Referência
CVE-2017-18256
Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert
23RIESGO
abrir
Referência
CVE-2012-0904
VLC media player 1.1.11 allows remote attackers to cause a denial of service (crash) via a long string in an amr file.
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Photoracer 1.0 - 'id' SQL Injection
CVE-2009-2122webappsphp
SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote atta
23RIESGO
abrir
Referência
CVE-2017-8477
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
23RIESGO
abrir
Referência
CVE-2023-4114
PHP Jabbers Night Club Booking Software index.php cross site scripting
48RIESGO
abrir
Referência
CVE-2014-1854
SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free p
23RIESGO
abrir
Referência
CVE-2017-13876
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Referência
CVE-2022-50794
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via Username
48RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.AVI' File Denial of Service
CVE-2007-0562doswindows
Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause
28RIESGO
abrir
ReferênciaVexDay Proof
Maian Recipe 1.0 - 'path_to_folder' Remote File Inclusion
CVE-2007-0848webappsphp
PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow (PoC)
CVE-2008-1709doswindows
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RIESGO
abrir
ReferênciaVexDay Proof
Carscripts Classifieds - 'cat' SQL Injection
CVE-2008-2844webappsphp
SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
Mitrastar GPT-2541GNAC-N1 - Privilege escalation
CVE-2021-42165remotehardware
MitraStar GPT-2541GNAC-N1 (HGU) 100VNZ0b33 devices allow remote authenticated users to obtain root access by executing c
28RIESGO
abrir
Referência
Webmin 1.996 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-36446webappslinux
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RIESGO
abrir
ReferênciaVexDay Proof
Vinagre < 2.24.2 - 'show_error()' Remote Format String (PoC)
CVE-2008-5660doswindows
Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2
23RIESGO
abrir
Referência
CVE-2022-36804
CVE-2022-36804HIGHbajo ataque
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
Referência
CVE-2014-0867
rcore6/main/addcookie.jsp in RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM A
23RIESGO
abrir
Referência
CVE-2022-36804
CVE-2022-36804HIGHbajo ataque
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 bef
100RIESGO
abrir
Referência
CVE-2018-10900
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac
56RIESGO
abrir
Referência
CVE-2010-2701
Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) th
23RIESGO
abrir
ReferênciaVexDay Proof
KVIrc 3.4.2 Shiny - URI handler Remote Command Execution
CVE-2008-7070remotewindows
Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary co
23RIESGO
abrir
Referência
CVE-2017-12950
The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL p
23RIESGO
abrir
Referência
CVE-2021-24308
LifterLMS < 4.21.1 - Authenticated Stored XSS in Edit Profile
23RIESGO
abrir
ReferênciaVexDay Proof
PayProCart 1146078425 - Multiple Remote File Inclusions
CVE-2006-4672webappsphp
PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
QK SMTP 3.01 - 'RCPT TO' Remote Denial of Service
CVE-2006-5551doswindows
Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a lon
23RIESGO
abrir
ReferênciaVexDay Proof
Ultimate PHP Board 2.0 - 'header_simple.php' File Inclusion
CVE-2006-7169webappsphp
PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows
23RIESGO
abrir
ReferênciaVexDay Proof
E-Smart Cart - 'productsofcat.asp' SQL Injection
CVE-2008-2917webappsasp
SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
anteriorpágina 575 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.