Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
21.534 exploits
Referência
CVE-2017-15220
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginni
23RIESGO
abrir
ReferênciaVexDay Proof
PumpKIN TFTP Server 2.7.2.0 - Denial of Service (Metasploit)
CVE-2008-6791doswindows
PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode fi
23RIESGO
abrir
Referência
Rukovoditel Project Management CRM 2.3.1 - Remote Code Execution (Metasploit)
CVE-2018-20166webappsphp
A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a
23RIESGO
abrir
Referência
CVE-2010-0631
Multiple SQL injection vulnerabilities in index.php in Eicra Car Rental-Script, when the plugin_id parameter is 4, allow
23RIESGO
abrir
Referência
CVE-2010-0632
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RIESGO
abrir
Referência
CVE-2010-0632
SQL injection vulnerability in the Parkview Consultants SimpleFAQ (com_simplefaq) component for Joomla! allows remote at
23RIESGO
abrir
Referência
CVE-2010-0642
Cisco Collaboration Server (CCS) 5 allows remote attackers to read the source code of JHTML files via URL encoded charac
23RIESGO
abrir
Referência
CVE-2021-25160
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
23RIESGO
abrir
ReferênciaVexDay Proof
0irc-client 1345 build20060823 - Denial of Service
CVE-2007-1648doswindows
0irc 1345 build 20060823 allows remote attackers to cause a denial of service (application crash) by operating an IRC se
23RIESGO
abrir
Referência
CVE-2013-5639
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir
Referência
CVE-2013-5639
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir
Referência
CVE-2020-11700
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.
23RIESGO
abrir
ReferênciaVexDay Proof
RealPlayer 10 - '.ra' Remote Denial of Service
CVE-2007-2497doswindows
RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain
23RIESGO
abrir
Referência
CVE-2013-1465
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to un
23RIESGO
abrir
Referência
CVE-2013-1465
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to un
23RIESGO
abrir
Referência
CVE-2015-2315
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Multiple Newsletters 2.7 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5566webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin E-Commerce 3.4 - Arbitrary File Upload
CVE-2008-6811webappsphp
Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress al
23RIESGO
abrir
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1057doswindows
MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that tri
23RIESGO
abrir
ReferênciaVexDay Proof
32bit FTP (09.04.24) - 'Banner' Remote Buffer Overflow (PoC)
CVE-2009-1592doswindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RIESGO
abrir
Referência
CVE-2013-3314
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2)
23RIESGO
abrir
Referência
CVE-2018-7706
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbit
23RIESGO
abrir
Referência
CVE-2014-2630
Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via u
38RIESGO
abrir
Referência
CVE-2019-16399
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to acce
23RIESGO
abrir
Referência
CVE-2010-2130
Cross-site scripting (XSS) vulnerability in wflogin.jsp in Aris Global ARISg 5.0 allows remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2018-12617
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 h
28RIESGO
abrir
Referência
CVE-2019-14267
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RIESGO
abrir
ReferênciaVexDay Proof
ASPPortal 3.1.1 - 'downloadid' SQL Injection
CVE-2006-1353webappsasp
Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Referência
CVE-2011-0403
Untrusted search path vulnerability in ImgBurn.exe in ImgBurn 2.4.0.0, 2.5.4.0, and other versions allows local users, a
23RIESGO
abrir
Referência
CVE-2014-5521
plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary co
23RIESGO
abrir
anteriorpágina 182 / 718siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.