Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
21.497 exploits
Referência
CVE-2014-10011
Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView ca
28RIESGO
abrir
Referência
CVE-2021-33904
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The
38RIESGO
abrir
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
CVE-2007-2816webappsphp
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component custompages 1.1 - Remote File Inclusion
CVE-2008-1505webappsphp
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joo
35RIESGO
abrir
ReferênciaVexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (1)
CVE-2008-2693remotewindows
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RIESGO
abrir
Referência
CVE-2020-5260
malicious URLs may cause Git to present stored credentials to the wrong server
48RIESGO
abrir
Referência
CVE-2018-8619
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest
35RIESGO
abrir
Referência
CVE-2018-12706
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
28RIESGO
abrir
Referência
CVE-2017-0263
CVE-2017-0263HIGHbajo ataque
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RIESGO
abrir
Referência
CVE-2006-0992
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute ar
60RIESGO
abrir
Referência
CVE-2017-17999
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Referência
CVE-2017-5972
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RIESGO
abrir
ReferênciaVexDay Proof
ActualAnalyzer - 'ant' Cookie Command Execution (Metasploit)
CVE-2014-5470CRITICALremoteunix
Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for pa
68RIESGO
abrir
Referência
CVE-2014-2223
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen
28RIESGO
abrir
Referência
CVE-2014-2223
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen
28RIESGO
abrir
ReferênciaVexDay Proof
Sugar Suite Open Source 4.2 - 'OptimisticLock' Command Execution
CVE-2006-2460webappsphp
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variable
28RIESGO
abrir
ReferênciaVexDay Proof
AtomixMP3 < 2.3 - '.m3u' Local Buffer Overflow
CVE-2006-6287localwindows
Stack-based buffer overflow in AtomixMP3 2.3 and earlier allows remote attackers to execute arbitrary code via a long pa
28RIESGO
abrir
Referência
CVE-2015-7245
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot
50RIESGO
abrir
Referência
CVE-2018-19043
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename)
28RIESGO
abrir
Referência
CVE-2018-19042
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di
28RIESGO
abrir
ReferênciaVexDay Proof
CA Internet Security Suite 2008 - 'SaveToFile()' File Corruption (PoC)
CVE-2008-2511doswindows
Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEv
28RIESGO
abrir
ReferênciaVexDay Proof
PlaySms 0.9.3 - Multiple Local/Remote File Inclusions
CVE-2009-0103webappsphp
Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code
28RIESGO
abrir
Referência
CVE-2017-17417
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
23RIESGO
abrir
Referência
Vtiger CRM 7.1.0 - Remote Code Execution
CVE-2019-5009webappsphp
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the upload
23RIESGO
abrir
Referência
CVE-2021-34370
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are
38RIESGO
abrir
Referência
CVE-2009-4427
Directory traversal vulnerability in cmd.php in phpLDAPadmin 1.1.0.5 allows remote attackers to include and execute arbi
23RIESGO
abrir
Referência
CVE-2018-17961
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RIESGO
abrir
Referência
CVE-2013-6283
VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex
23RIESGO
abrir
Referência
CVE-2009-4958
SQL injection vulnerability in video.php in EMO Breeder Manager (aka EMO Breader Manager) allows remote attackers to exe
23RIESGO
abrir
Referência
CVE-2014-5109
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attacker
23RIESGO
abrir
anteriorpágina 152 / 717siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.