Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
ReferênciaVexDay Proof
DeluxeBB 1.07 - Remote Create Admin
CVE-2006-3304webappsphp
SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2014-8440
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on
60RIESGO
abrir
Referência
CVE-2015-0336
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451
60RIESGO
abrir
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3302webappsphp
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote aut
23RIESGO
abrir
Referência
CVE-2017-8779
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider t
60RIESGO
abrir
Referência
CVE-2020-35578
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir
Referência
CVE-2020-35578
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir
Referência
CVE-2023-22232
Adobe Connect Improper Access Control Security feature bypass
70RIESGO
abrir
Referência
CVE-2019-5392
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RIESGO
abrir
Referência
CVE-2009-2428
Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3304webappsphp
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to fo
23RIESGO
abrir
Referência
CVE-2019-5418
CVE-2019-5418HIGHbajo ataque
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
ReferênciaVexDay Proof
Pre Survey Poll - 'catid' SQL Injection
CVE-2008-3310webappsasp
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
feedDemon 2.7 - OPML Outline Tag Buffer Overflow
CVE-2009-0546localwindows
Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbi
50RIESGO
abrir
Referência
CVE-2017-17641
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
LetterIt 2 - 'Language' Local File Inclusion
CVE-2008-3446webappsphp
Directory traversal vulnerability in inc/wysiwyg.php in LetterIt 2 allows remote attackers to include and execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
F-PROT AntiVirus 6.2.1.4252 - Malformed Archive Infinite Loop Denial of Service
CVE-2008-3447dosmultiple
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop)
23RIESGO
abrir
Referência
CVE-2017-0070
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
35RIESGO
abrir
ReferênciaVexDay Proof
eNdonesia 8.4 (Calendar Module) - SQL Injection
CVE-2008-3452webappsphp
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Hosting Directory 2.0 - Insecure Cookie Handling
CVE-2008-3454webappsphp
JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by se
23RIESGO
abrir
Referência
CVE-2014-5301
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RIESGO
abrir
ReferênciaVexDay Proof
WebMaster Marketplace - SQL Injection
CVE-2008-5574webappsphp
SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2021-1732
CVE-2021-1732HIGHbajo ataqueransomware
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Referência
CVE-2021-1732
CVE-2021-1732HIGHbajo ataqueransomware
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Referência34
CVE-2024-23108: Fortinet FortiSIEM Unauthenticated 2nd Order Command Injection
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RIESGO
abrir
Referência
CVE-2012-3873
Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Hosting Directory 2.0 - Remote File Inclusion
CVE-2008-3455webappsphp
PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attacke
23RIESGO
abrir
Referência
CVE-2008-5585
Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2017-12478
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir
Referência
CVE-2017-12478
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.