Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
Referência
CVE-2014-4699
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RIESGO
abrir
Referência
Printix Client 1.3.1106.0 - Remote Code Execution (RCE)
CVE-2022-25089remotewindows
Printix Secure Cloud Print Management through 1.3.1106.0 incorrectly uses Privileged APIs to modify values in HKEY_LOCAL
28RIESGO
abrir
Referência
CVE-2018-17310
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of add
23RIESGO
abrir
Referência
CVE-2015-4591
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RIESGO
abrir
Referência
CVE-2011-10017
Snort Report nmap.php/nbtscan.php RCE
63RIESGO
abrir
Referência
CVE-2011-10017
Snort Report nmap.php/nbtscan.php RCE
63RIESGO
abrir
Referência
CVE-2017-2509
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RIESGO
abrir
ReferênciaVexDay Proof
MySpeach 3.0.7 - Local/Remote File Inclusion
CVE-2007-1895webappsphp
PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, all
23RIESGO
abrir
Referência
CVE-2012-1211
Cross-site scripting (XSS) vulnerability in pfile/kommentar.php in Powie pFile 1.02 allows remote attackers to inject ar
23RIESGO
abrir
ReferênciaVexDay Proof
Evilsentinel 1.0.9 - Multiple Vulnerabilities Disable
CVE-2008-0351webappsphp
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es
23RIESGO
abrir
Referência
CVE-2012-2911
Cross-site scripting (XSS) vulnerability in backupDB.php in SiliSoftware backupDB() 1.2.7a allows remote attackers to in
23RIESGO
abrir
Referência
CVE-2013-2028
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir
Referência
CVE-2014-4718
Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack th
23RIESGO
abrir
Referência
CVE-2014-4718
Multiple cross-site request forgery (CSRF) vulnerabilities in Lunar CMS before 3.3-3 allow remote attackers to hijack th
23RIESGO
abrir
Referência
CVE-2009-4693
Multiple PHP remote file inclusion vulnerabilities in GraFX MiniCWB 2.3.0 allow remote attackers to execute arbitrary PH
23RIESGO
abrir
Referência
CVE-2009-5089
Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary file
23RIESGO
abrir
Referência
CVE-2013-7184
Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption
23RIESGO
abrir
Referência
CVE-2015-8398
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitra
23RIESGO
abrir
Referência
CVE-2015-3624
Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content
23RIESGO
abrir
Referência
CVE-2015-3624
Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content
23RIESGO
abrir
Referência
CVE-2012-1898
Multiple cross-site scripting (XSS) vulnerabilities in wolfcms/admin/user/add in Wolf CMS 0.75 and earlier allow remote
23RIESGO
abrir
ReferênciaVexDay Proof
Adobe Reader - 'util.printf()' JavaScript Function Stack Overflow (2)
CVE-2008-2992HIGHbajo ataqueransomwarelocalwindows
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RIESGO
abrir
ReferênciaVexDay Proof
Libra PHP File Manager 1.18/2.0 - Local File Inclusion
CVE-2008-4319webappsphp
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass auth
23RIESGO
abrir
Referência
CVE-2013-2094
CVE-2013-2094HIGHbajo ataque
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir
ReferênciaVexDay Proof
Minerva 2.0.8a Build 237 - 'phpbb_root_path' File Inclusion
CVE-2006-3028webappsphp
PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier all
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Update 2.7 - '/admin/uploads.php' Remote Code Execution
CVE-2006-6878webappsphp
admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] para
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component module autostand 1.0 - Remote File Inclusion
CVE-2007-2319webappsphp
PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Blakord Portal Beta 1.3.A (All Modules) - SQL Injection
CVE-2007-6565webappsphp
Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2016-3670
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1
23RIESGO
abrir
Referência
CVE-2010-2655
Directory traversal vulnerability in private/file_management.php on the IBM BladeCenter with Advanced Management Module
23RIESGO
abrir
anteriorpágina 637 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.