Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.801exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2017-6443
Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Referência
CVE-2012-1258
cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow Analyzer before 9.0.1.19899 does not validate
23RIESGO
abrir
Referência
CVE-2014-9225
The ajaxswing webui in the management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symante
23RIESGO
abrir
Referência
CVE-2009-3428
Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted
23RIESGO
abrir
Referência
CVE-2009-3428
Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted
23RIESGO
abrir
Referência
CVE-2009-3428
Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted
23RIESGO
abrir
ReferênciaVexDay Proof
WebPortal CMS 0.8b - Multiple Local/Remote File Inclusions
CVE-2009-1445webappsphp
Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary file
23RIESGO
abrir
Referência
CVE-2015-3898
Multiple open redirect vulnerabilities in Bonita BPM Portal before 6.5.3 allow remote attackers to redirect users to arb
23RIESGO
abrir
Referência
CVE-2017-2514
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir
Referência
CVE-2014-100014
Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to
23RIESGO
abrir
Referência
CVE-2010-0832
pam_motd (aka the MOTD module) in libpam-modules before 1.1.0-2ubuntu1.1 in PAM on Ubuntu 9.10 and libpam-modules before
23RIESGO
abrir
Referência
CVE-2017-17593
Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.
23RIESGO
abrir
Referência
CVE-2017-17593
Simple Chatting System 1.0 allows Arbitrary File Upload via view/my_profile.php, which places files under uploads/.
23RIESGO
abrir
Referência
CVE-2011-0405
Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc i
23RIESGO
abrir
ReferênciaVexDay Proof
VImpX ActiveX (VImpX.ocx 4.7.3.0) - Remote Buffer Overflow
CVE-2007-2667remotewindows
Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Ruby 1.8.6/1.9 (WEBick HTTPd 1.3.1) - Directory Traversal
CVE-2008-1145remotemultiple
Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when
28RIESGO
abrir
Referência
CVE-2016-8023
Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3
23RIESGO
abrir
Referência
CVE-2022-4395
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
Referência
CVE-2018-19550
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit
23RIESGO
abrir
Referência
CVE-2023-2779
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Referência
CVE-2023-2779
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Referência
CVE-2023-2779
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Referência
CVE-2010-4884
PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
TYPSoft FTP Server 1.11 - 'ABORT' Remote Denial of Service
CVE-2009-1668doswindows
TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort
23RIESGO
abrir
Referência
CVE-2020-16602
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a ra
23RIESGO
abrir
ReferênciaVexDay Proof
CliServ Web Community 0.65 - 'cl_headers' Include
CVE-2006-7068webappsphp
PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arb
23RIESGO
abrir
Referência
CVE-2017-3631
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir
Referência
CVE-2017-3631
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir
ReferênciaVexDay Proof
TEC-IT TBarCode - OCX ActiveX Arbitrary File Overwrite
CVE-2007-3233remotewindows
The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files
23RIESGO
abrir
Referência
CVE-2009-3531
SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
anteriorpágina 570 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.