Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
21.534 exploits
ReferênciaVexDay Proof
jetAudio 7.0.5 - '.asx' Remote Stack Overflow (PoC)
CVE-2008-0747doswindows
Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute
23RIESGO
abrir
Referência
CVE-2016-8580
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vuln
23RIESGO
abrir
ReferênciaVexDay Proof
HP Software Update - 'Hpufunction.dll 4.0.0.1' Insecure Method
CVE-2008-2390remotewindows
Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows
23RIESGO
abrir
Referência
CVE-2009-1642
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2014-4076
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir
Referência
CVE-2014-4076
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir
Referência
CVE-2009-4756
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2009-4756
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2009-4756
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2009-4756
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2013-1592
A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending speci
28RIESGO
abrir
Referência
CVE-2015-3246
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
38RIESGO
abrir
Referência
CVE-2010-0690
SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2014-5194
Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbi
23RIESGO
abrir
Referência
CVE-2009-4699
Multiple cross-site scripting (XSS) vulnerabilities in SkaDate Dating allow remote attackers to inject arbitrary web scr
23RIESGO
abrir
Referência
CVE-2015-8283
Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
23RIESGO
abrir
Referência
CVE-2015-8283
Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
23RIESGO
abrir
Referência
CVE-2011-5162
Stack-based buffer overflow in GOM Player 2.1.33.5071 allows user-assisted remote attackers to execute arbitrary code vi
23RIESGO
abrir
ReferênciaVexDay Proof
eXtremail 2.1.1 - DNS Parsing Bugs Remote (PoC)
CVE-2007-2187doslinux
Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long
23RIESGO
abrir
ReferênciaVexDay Proof
phpBBViet 02.03.2007 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-6088webappsphp
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBBViet 02.03.07 and earlier allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
CVE-2007-6489webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbi
23RIESGO
abrir
Referência
CVE-2015-3001
SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which al
23RIESGO
abrir
Referência
CVE-2018-6889
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a m
23RIESGO
abrir
Referência
CVE-2016-1910
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors,
23RIESGO
abrir
ReferênciaVexDay Proof
KnowledgeQuest 2.5 - Arbitrary Add Admin
CVE-2008-1727webappsphp
KnowledgeQuest 2.5 and 2.6 does not require authentication for access to admincheck.php, which allows remote attackers t
23RIESGO
abrir
Referência
CVE-2017-0085
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
Referência
CVE-2017-2527
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimati
23RIESGO
abrir
ReferênciaVexDay Proof
Google Chrome - Carriage Return Null Object Memory Exhaustion
CVE-2008-4340doswindows
Google Chrome 0.2.149.29 and 0.2.149.30 allows remote attackers to cause a denial of service (memory consumption) via an
23RIESGO
abrir
ReferênciaVexDay Proof
VideoScript 4.0.1.50 - Change Admin Password
CVE-2008-5219webappsphp
The password change feature (admin/cp.php) in VideoScript 4.0.1.50 and earlier does not check for administrative authent
23RIESGO
abrir
Referência
CVE-2017-0119
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
anteriorpágina 171 / 718siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.