Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
20.023 exploits
Referência
WengoPhone 2.x - SIP Phone Remote Denial of Service
WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Co
23RIESGO
abrir
Referência
CVE-2014-9350
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attack
23RIESGO
abrir
Referência
CVE-2014-9350
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attack
23RIESGO
abrir
Referência
CVE-2012-0292
The awhost32 service in Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.
23RIESGO
abrir
Referência
CVE-2014-3418
config/userAdmin/login.tdf in Infoblox NetMRI before 6.8.5 allows remote attackers to execute arbitrary commands via she
23RIESGO
abrir
Referência
WordPress Core 2.1.2 - 'xmlrpc' SQL Injection
SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated
23RIESGO
abrir
Referência
CVE-2015-5533
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote
23RIESGO
abrir
Referência
CVE-2015-5533
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote
23RIESGO
abrir
Referência
CVE-2021-21276
Privilege escalation in Polr
48RIESGO
abrir
Referência
CVE-2016-15048
AMTT HiBOS Command Injection RCE via server_ping.php
48RIESGO
abrir
Referência
CVE-2022-24707
SQL injection in anuko timetracker
41RIESGO
abrir
Referência
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir
Referência
Pi3Web 2.0.3 - 'ISAPI' Remote Denial of Service
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RIESGO
abrir
Referência
RM Downloader - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
Referência
RM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
Referência
CVE-2023-36346
POS Codekop v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the nm_member parame
38RIESGO
abrir
Referência
CVE-2010-2032
Multiple cross-site scripting (XSS) vulnerabilities in resin-admin/digest.php in Caucho Technology Resin Professional 3.
23RIESGO
abrir
Referência
CVE-2016-1001
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows an
28RIESGO
abrir
Referência
CVE-2014-2994
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to exec
28RIESGO
abrir
Referência
CVE-2014-2994
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to exec
28RIESGO
abrir
Referência
CVE-2014-2994
Stack-based buffer overflow in Acunetix Web Vulnerability Scanner (WVS) 8 build 20120704 allows remote attackers to exec
28RIESGO
abrir
Referência
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir
Referência
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir
Referência
Simple Machines Forum (SMF) 1.1.5 (Windows x86) - Admin Reset Password
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before
23RIESGO
abrir
Referência
CVE-2022-31056
SQL injection with _actor parameter in GLPI
48RIESGO
abrir
Referência
Rukovoditel Project Management CRM 2.3.1 - Remote Code Execution (Metasploit)
A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a
23RIESGO
abrir
Referência
CVE-2015-2314
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary S
23RIESGO
abrir
Referência
PHPWebGallery 1.7.2 - Session Hijacking / Code Execution
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to exe
23RIESGO
abrir
Referência
CVE-2010-4333
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrativ
23RIESGO
abrir
Referência
CVE-2017-6351
The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password
23RIESGO
abrir
anteriorpágina 150 / 668siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.