Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
21.534 exploits
Referência
CVE-2013-4859
INSTEON Hub 2242-222 lacks Web and API authentication
23RIESGO
abrir
Referência
CVE-2017-15270
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) f
23RIESGO
abrir
Referência
CVE-2017-15270
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) f
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Spider Friendly Module 1.3.10 - Remote File Inclusion
CVE-2006-5665webappsphp
PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier
23RIESGO
abrir
ReferênciaVexDay Proof
Active PHP Bookmark Notes 0.2.5 - Remote File Inclusion
CVE-2007-1621webappsphp
PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allow
23RIESGO
abrir
ReferênciaVexDay Proof
Clever Internet ActiveX Suite 6.2 - Arbitrary File Download/Overwrite
CVE-2007-4067remotewindows
Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Inter
23RIESGO
abrir
Referência
CVE-2019-1914
Cisco Small Business 220 Series Smart Switches Command Injection Vulnerability
46RIESGO
abrir
Referência
CVE-2015-8358
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators t
23RIESGO
abrir
Referência
CVE-2015-8358
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators t
23RIESGO
abrir
Referência
CVE-2017-2363
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir
Referência
CVE-2014-3008
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacte
23RIESGO
abrir
Referência
CVE-2017-3316
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions tha
23RIESGO
abrir
Referência
CVE-2013-2121
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote
43RIESGO
abrir
Referência
CVE-2017-2932
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript
28RIESGO
abrir
ReferênciaVexDay Proof
Visual Basic Enterprise Edition SP6 - 'vb6skit.dll' Buffer Overflow (PoC)
CVE-2008-2959doswindows
Buffer overflow in a certain ActiveX control (vb6skit.dll) in Microsoft Visual Basic Enterprise Edition 6.0 SP6 might al
28RIESGO
abrir
ReferênciaVexDay Proof
Foxmail 5.0 - 'PunyLib.dll' Remote Stack Overflow
CVE-2004-2719remotewindows
Buffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
X10media Mp3 Search Engine 1.6 - Remote File Disclosure
CVE-2008-6960webappsphp
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitr
23RIESGO
abrir
Referência
CVE-2015-7896
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memor
23RIESGO
abrir
Referência
CVE-2015-7896
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memor
23RIESGO
abrir
Referência
CVE-2010-4332
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative pr
23RIESGO
abrir
ReferênciaVexDay Proof
PHP iCalendar 2.21 - 'publish.ical.php' Remote Code Execution
CVE-2006-1291webappsphp
publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write acce
23RIESGO
abrir
Referência
CVE-2017-17097
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords
23RIESGO
abrir
ReferênciaVexDay Proof
SmartSite CMS 1.0 - 'root' Remote File Inclusion
CVE-2006-3162webappsphp
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2014-1637
Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which a
23RIESGO
abrir
ReferênciaVexDay Proof
GuppY 4.5.16 - Remote Command Execution
CVE-2007-0639webappsphp
Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject
23RIESGO
abrir
ReferênciaVexDay Proof
Sun xVM VirtualBox < 1.6.4 - Privilege Escalation (PoC)
CVE-2008-3431HIGHbajo ataquedosmultiple
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communicat
71RIESGO
abrir
ReferênciaVexDay Proof
DFLabs PTK 1.0 - Local Command Execution
CVE-2008-6793webappsphp
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2014-2399
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attacker
23RIESGO
abrir
Referência
CVE-2014-2399
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 2.2.2 allows remote attacker
23RIESGO
abrir
Referência
CVE-2011-3713
cFTP r80 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the
23RIESGO
abrir
anteriorpágina 185 / 718siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.