Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.837exploits catalogados
35.811CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.572GitHub PoC 14.291VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.549 exploits
Referência
CVE-2015-7293
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef
23RIESGO
abrir ↗Referência
CVE-2015-7293
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef
23RIESGO
abrir ↗Referência
CVE-2017-11330
The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denia
23RIESGO
abrir ↗Referência
Core FTP 2.0 - 'XRMD' Denial of Service (PoC)
The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon cr
23RIESGO
abrir ↗Referência
CVE-2008-7185
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlis
23RIESGO
abrir ↗Referência
CVE-2021-37531
SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerabili
48RIESGO
abrir ↗Referência
CVE-2007-5982
Multiple cross-site scripting (XSS) vulnerabilities in X7 Chat 2.0.4, 2.0.5, and possibly other versions allow remote at
23RIESGO
abrir ↗Referência
CVE-2015-1482
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive inform
23RIESGO
abrir ↗Referência
CVE-2015-1482
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive inform
23RIESGO
abrir ↗Referência
CVE-2010-3213
Cross-site request forgery (CSRF) vulnerability in Microsoft Outlook Web Access (owa/ev.owa) 2007 through SP2 allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
KwsPHP - 'Upload' Remote Code Execution
Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allo
23RIESGO
abrir ↗Referência
CVE-2009-4264
PHP remote file inclusion vulnerability in components/core/connect.php in AROUNDMe 1.1 and earlier, when register_global
23RIESGO
abrir ↗Referência
CVE-2017-13260
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RIESGO
abrir ↗Referência
CVE-2012-5858
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-m
23RIESGO
abrir ↗Referência
CVE-2014-3738
Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir ↗Referência✓ VexDay Proof
zeeproperty 1.0 - Arbitrary File Upload / Cross-Site Scripting
Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users t
23RIESGO
abrir ↗Referência✓ VexDay Proof
mxBB Module calsnails 1.06 - 'mx_common.php' File Inclusion
PHP remote file inclusion vulnerability in includes/mx_common.php in the CalSnails Module for MxBB Portal 1.06 allows re
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpLinkat 0.1 - Insecure Cookie Handling / SQL Injection
phpLinkat 0.1 allows remote attackers to bypass authentication and access unspecified pages under admin/ by sending a lo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Camera Life 2.6.2b4 - Arbitrary File Upload
Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated
23RIESGO
abrir ↗Referência
CVE-2017-17607
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
23RIESGO
abrir ↗Referência
CVE-2017-17607
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
23RIESGO
abrir ↗Referência
CVE-2014-3792
Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote at
23RIESGO
abrir ↗Referência
CVE-2015-2805
Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web int
23RIESGO
abrir ↗Referência
CVE-2015-2805
Cross-site request forgery (CSRF) vulnerability in sec/content/sec_asa_users_local_db_add.html in the management web int
23RIESGO
abrir ↗Referência
CVE-2010-0605
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Sta
23RIESGO
abrir ↗Referência
CVE-2010-0605
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Sta
23RIESGO
abrir ↗Referência
CVE-2010-1873
SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote at
23RIESGO
abrir ↗Referência
CVE-2010-1873
SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote at
23RIESGO
abrir ↗Referência
CVE-2009-4360
SQL injection vulnerability in modules/content/index.php in the Content module 0.5 for XOOPS allows remote attackers to
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.