Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
Referência
CVE-2018-8474
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa
35RIESGO
abrir
Referência
CVE-2018-7658
NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service
35RIESGO
abrir
Referência
CVE-2018-7658
NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service
35RIESGO
abrir
Referência
CVE-2015-2843
Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute
50RIESGO
abrir
Referência
IOTransfer V4 - Unquoted Service Path
CVE-2022-37197HIGHlocalwindows
IOBit IOTransfer V4 is vulnerable to Unquoted Service Path.
41RIESGO
abrir
ReferênciaVexDay Proof
Apple QuickTime 7.2/7.3 (OSX/Windows) - RSTP Response Universal
CVE-2002-0252remotemultiple
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a respon
28RIESGO
abrir
Referência
CVE-2022-0482
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
75RIESGO
abrir
Referência
CVE-2022-47878
Incorrect input validation for the default-storage-path in the settings page in Jedox 2020.2.5 allows remote, authentica
60RIESGO
abrir
Referência
CVE-2019-10945
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RIESGO
abrir
Referência
CVE-2019-10945
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RIESGO
abrir
Referência
CVE-2021-3817
SQL Injection in wbce/wbce_cms
60RIESGO
abrir
Referência
CVE-2013-2751
Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator
60RIESGO
abrir
Referência
CVE-2019-16893
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the
35RIESGO
abrir
ReferênciaVexDay Proof
PHP Project Management 0.8.10 - Multiple Local/Remote File Inclusions
CVE-2007-5642webappsphp
Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to incl
23RIESGO
abrir
ReferênciaVexDay Proof
AAA EasyGrid ActiveX 3.51 - Remote File Overwrite
CVE-2009-0134remotewindows
Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX
23RIESGO
abrir
Referência
CVE-2022-26965
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remot
35RIESGO
abrir
Referência
CVE-2016-1101
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
Referência
CVE-2016-1101
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (PoC)
CVE-2009-0174doswindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' 'HREF' Universal Buffer Overflow
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (2)
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RIESGO
abrir
Referência
CVE-2010-0688
Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a
50RIESGO
abrir
Referência
CVE-2018-7582
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to
35RIESGO
abrir
Referência
CVE-2018-7582
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to
35RIESGO
abrir
Referência
CVE-2017-6884
CVE-2017-6884HIGHbajo ataqueransomware
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vul
83RIESGO
abrir
ReferênciaVexDay Proof
Free Download Manager 2.5/3.0 - Authorisation Stack Buffer Overflow (PoC)
CVE-2009-0183doswindows
Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allo
50RIESGO
abrir
ReferênciaVexDay Proof
Ultra Shareware Office Control - ActiveX Control Remote Buffer Overflow
CVE-2008-3878remotewindows
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware
50RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component mp3 allopass 1.0 - Remote File Inclusion
CVE-2007-5412webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joo
35RIESGO
abrir
Referência
CVE-2019-0752
CVE-2019-0752HIGHbajo ataqueransomware
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
ReferênciaVexDay Proof
Realtek Sound Manager (rtlrack.exe 1.15.0.0) - Playlist Buffer Overflow
CVE-2008-5664localwindows
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.