Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
21.797 exploits
Referência
CVE-2010-4401
languages.inc.php in DynPG CMS 4.2.0 allows remote attackers to obtain sensitive information via a direct request, which
23RIESGO
abrir
Referência
CVE-2009-4775
Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of
23RIESGO
abrir
Referência
CVE-2009-4775
Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of
23RIESGO
abrir
Referência
CVE-2017-15035
EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).
23RIESGO
abrir
Referência
CVE-2016-1415
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of servi
23RIESGO
abrir
ReferênciaVexDay Proof
Ultra Crypto Component - 'CryptoX.dll 2.0 SaveToFile()' Insecure Method
CVE-2007-4902remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Co
23RIESGO
abrir
Referência
CVE-2014-3139
recoveryconsole/bpl/snmpd.php in Unitrends Enterprise Backup 7.3.0 allows remote attackers to bypass authentication by s
23RIESGO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)
CVE-2008-2573doswindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
SyndeoCMS 2.6.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5272webappsphp
Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read a
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS 2.3.1 - Multiple Local File Inclusions
CVE-2008-6884webappsphp
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to
23RIESGO
abrir
Referência
CVE-2018-11505
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp
23RIESGO
abrir
Referência
CVE-2011-5219
Directory traversal vulnerability in examples/show_code.php in mPDF 5.3 and earlier allows remote attackers to read arbi
23RIESGO
abrir
Referência
CVE-2021-25680
The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These
23RIESGO
abrir
Referência
CVE-2010-1053
Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow re
23RIESGO
abrir
Referência
CVE-2016-3974
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remo
28RIESGO
abrir
Referência
CVE-2017-15287
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouq
38RIESGO
abrir
Referência
CVE-2016-3974
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remo
28RIESGO
abrir
Referência
CVE-2017-11319
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and c
23RIESGO
abrir
Referência
CVE-2017-11319
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and c
23RIESGO
abrir
Referência
CVE-2009-2379
Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execu
23RIESGO
abrir
Referência
CVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled,
23RIESGO
abrir
Referência
CVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled,
23RIESGO
abrir
Referência
CVE-2019-7400
Rukovoditel before 2.4.1 allows XSS.
23RIESGO
abrir
Referência
CVE-2019-7400
Rukovoditel before 2.4.1 allows XSS.
23RIESGO
abrir
Referência
CVE-2017-16543
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated
23RIESGO
abrir
ReferênciaVexDay Proof
Snort 2.6.1.1/2.6.1.2/2.7.0 - 'fragementation' Remote Denial of Service
CVE-2007-1398dosmultiple
The frag3 preprocessor in Snort 2.6.1.1, 2.6.1.2, and 2.7.0 beta, when configured for inline use on Linux without the ip
23RIESGO
abrir
Referência
CVE-2012-6307
A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious
23RIESGO
abrir
ReferênciaVexDay Proof
MP3 TrackMaker 1.5 - '.mp3' Local Heap Overflow (PoC)
CVE-2009-0175doswindows
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (
23RIESGO
abrir
ReferênciaVexDay Proof
db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities
CVE-2008-4750remotewindows
Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, po
23RIESGO
abrir
ReferênciaVexDay Proof
TLS - Renegotiation
CVE-2009-3555CRITICALremotemultiple
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RIESGO
abrir
anteriorpágina 311 / 727siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.