Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
20.023 exploits
Referência
CVE-2011-1591
Stack-based buffer overflow in the DECT dissector in epan/dissectors/packet-dect.c in Wireshark 1.4.x before 1.4.5 allow
50RIESGO
abrir
Referência
CVE-2024-25153
Remote Code Execution in FileCatalyst Workflow 5.x prior to 5.1.6 Build 114
60RIESGO
abrir
Referência
CVE-2019-0841
CVE-2019-0841HIGHbajo ataqueransomware
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
Referência
CVE-2018-16946
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /u
23RIESGO
abrir
Referência
CVE-2013-4096
ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary
23RIESGO
abrir
Referência
PHP mSQL (msql_connect) - Local Buffer Overflow (PoC)
Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a lo
23RIESGO
abrir
Referência
CVE-2013-1595
A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the
35RIESGO
abrir
Referência
PMECMS 1.0 - config[pathMod] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in PMECMS 1.0 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2010-2004
Stack-based buffer overflow in BS.Global BS.Player 2.51 Build 1022 Free, and possibly other versions, allows user-assist
23RIESGO
abrir
Referência
CVE-2022-26149
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an ex
23RIESGO
abrir
Referência
Youngzsoft CMailServer 5.4.6 - 'CMailCOM.dll' Remote Overwrite (SEH)
Multiple stack-based buffer overflows in CMailCOM.dll in CMailServer 5.4.6 allow remote attackers to execute arbitrary c
23RIESGO
abrir
Referência
CVE-2019-14347
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RIESGO
abrir
Referência
CVE-2015-3704
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly dro
23RIESGO
abrir
Referência
CVE-2015-3704
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly dro
23RIESGO
abrir
Referência
CVE-2016-1336
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a
23RIESGO
abrir
Referência
CVE-2016-1328
goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a
23RIESGO
abrir
Referência
AFGB Guestbook 2.2 - 'Htmls' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
Referência
muvee autoProducer 6.1 - 'TextOut.dll' ActiveX Remote Buffer Overflow
Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll
23RIESGO
abrir
Referência
Social Groupie - 'create_album.php' Arbitrary File Upload
Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to
23RIESGO
abrir
Referência
ablespace 1.0 - Cross-Site Scripting / Blind SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
Referência
e107 Plugin BLOG Engine 2.1.4 - SQL Injection
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RIESGO
abrir
Referência
Winamp GEN_MSN Plugin - Heap Buffer Overflow (PoC)
Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute
23RIESGO
abrir
Referência
Cyberfolio 2.0 RC1 - 'av' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Cyberfolio 2.0 RC1 and earlier, when register_globals is enabled,
23RIESGO
abrir
Referência
CVE-2017-6994
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir
Referência
CVE-2019-12279
Nagios XI 5.6.1 allows SQL injection via the username parameter to login.php?forgotpass (aka the reset password form). N
23RIESGO
abrir
Referência
Eskolar CMS 0.9.0.0 - Blind SQL Injection
Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
Page Manager CMS 2006-02-04 - Arbitrary File Upload
Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbit
23RIESGO
abrir
Referência
IP3 NetAccess < 4.1.9.6 - Arbitrary File Disclosure
Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allo
23RIESGO
abrir
Referência
CVE-2006-3683
PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute a
23RIESGO
abrir
Referência
CVE-2015-4073
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to exe
23RIESGO
abrir
anteriorpágina 164 / 668siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.