Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
ReferênciaVexDay Proof
March Networks DVR 3204 - Logfile Information Disclosure
CVE-2007-6638remotehardware
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows r
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component beamospetition - SQL Injection
CVE-2008-3132webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
BareNuked CMS 1.1.0 - Arbitrary Add Admin
CVE-2008-3133webappsphp
SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir
Referência
CVE-2024-6460
Grow by Tradedoubler <= 2.0.21 - Unauthenticated LFI
63RIESGO
abrir
Referência
CVE-2015-7235
Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for Wo
23RIESGO
abrir
Referência
CVE-2018-20326
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RIESGO
abrir
Referência
CVE-2018-20326
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RIESGO
abrir
Referência
CVE-2009-2736
Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators t
23RIESGO
abrir
Referência
CVE-2009-4372
AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows
23RIESGO
abrir
Referência
CVE-2015-6008
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands
23RIESGO
abrir
Referência
CVE-2025-4094
Digits < 8.4.6.1 - Auth Bypass via OTP Bruteforcing
53RIESGO
abrir
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1059doswindows
Stack-based buffer overflow in Trident PowerZip 7.2 might allow remote attackers to execute arbitrary code via a crafted
23RIESGO
abrir
ReferênciaVexDay Proof
Winamp 5.21 - '.Midi' File Header Handling Buffer Overflow (PoC)
CVE-2006-3228doswindows
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary
28RIESGO
abrir
Referência
CVE-2017-15374
Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management
23RIESGO
abrir
Referência
CVE-2009-2961
Stack-based buffer overflow in Thaddy de Konng KOL Player 1.0 allows remote attackers to cause a denial of service (cras
23RIESGO
abrir
Referência
CVE-2009-3947
Buffer overflow in the FTP service on the Tandberg MXP F7.0 allows remote attackers to cause a denial of service (proces
23RIESGO
abrir
Referência
CVE-2009-4759
Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) o
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.x COM - Safe Mode / disable_functions Bypass
CVE-2007-5653localwindows
The Component Object Model (COM) functions in PHP 5.x on Windows do not follow safe_mode and disable_functions restricti
23RIESGO
abrir
ReferênciaVexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Buffer Overflow (PoC)
CVE-2008-0661doswindows
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RIESGO
abrir
Referência
CVE-2011-2543
Buffer overflow in the cuil component in Cisco Telepresence System Integrator C Series 4.x before TC4.2.0 allows remote
28RIESGO
abrir
ReferênciaVexDay Proof
WebXell Editor 0.1.3 - Arbitrary File Upload
CVE-2008-3178webappsphp
Unrestricted file upload vulnerability in upload_pictures.php in WebXell Editor 0.1.3 allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2009-3960
CVE-2009-3960MEDIUMbajo ataqueransomware
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service
100RIESGO
abrir
Referência
CVE-2010-4278
operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary comm
28RIESGO
abrir
Referência
CVE-2017-9812
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus f
28RIESGO
abrir
Referência
CVE-2017-9812
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus f
28RIESGO
abrir
Referência
CVE-2009-2764
Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of
28RIESGO
abrir
Referência
CVE-2018-14418
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
23RIESGO
abrir
Referência
CVE-2017-16953
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo
28RIESGO
abrir
Referência
CVE-2009-3254
Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via
23RIESGO
abrir
Referência
CVE-2019-7439
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
23RIESGO
abrir
anteriorpágina 579 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.