Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
Referência
CVE-2018-11509
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applicat
28RIESGO
abrir
Referência
CVE-2018-11509
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applicat
28RIESGO
abrir
Referência
CVE-2014-6435
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication,
28RIESGO
abrir
ReferênciaVexDay Proof
Carom3D 5.06 - Unicode Buffer Overrun/Denial of Service
CVE-2009-2173doswindows
The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) v
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
CVE-2009-2176webappsphp
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, al
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
CVE-2009-2177webappsphp
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to con
23RIESGO
abrir
Referência
CVE-2018-19861
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD re
28RIESGO
abrir
Referência
CVE-2018-19861
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD re
28RIESGO
abrir
ReferênciaVexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
CVE-2009-2179webappsphp
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2019-6272
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attacker
28RIESGO
abrir
Referência
CVE-2019-15889
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t
53RIESGO
abrir
Referência
CVE-2019-15889
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t
53RIESGO
abrir
Referência
CVE-2009-2776
SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Referência
CVE-2010-1727
SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2015-5354
Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites
43RIESGO
abrir
Referência
CVE-2015-5354
Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites
43RIESGO
abrir
Referência
CVE-2009-4733
SQL injection vulnerability in checkuser.php in SimpleLoginSys 0.5, when magic_quotes_gpc is disabled, allows remote att
23RIESGO
abrir
Referência
CVE-2014-8675
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which all
28RIESGO
abrir
Referência
CVE-2014-8675
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which all
28RIESGO
abrir
Referência
CVE-2016-2056
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via
50RIESGO
abrir
Referência
CVE-2010-1727
SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2019-19774
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetai
28RIESGO
abrir
Referência
CVE-2017-5630
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenam
28RIESGO
abrir
Referência
CVE-2016-2056
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via
50RIESGO
abrir
ReferênciaVexDay Proof
pc4 Uploader 10.0 - Remote File Disclosure
CVE-2009-2180webappsphp
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2183webappsphp
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possib
23RIESGO
abrir
Referência
CVE-2018-15705
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f
28RIESGO
abrir
Referência
CVE-2020-15500
An issue was discovered in server.js in TileServer GL through 3.0.0. The content of the key GET parameter is reflected u
43RIESGO
abrir
ReferênciaVexDay Proof
Adobe Acrobat 9 - ActiveX Remote Denial of Service
CVE-2008-4071doswindows
A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows rem
28RIESGO
abrir
Referência
CVE-2018-5406
The Quest Kace K1000 Appliance misconfigures the Cross-Origin Resource Sharing (CORS) mechanism.
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.