Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
Referência
CVE-2017-1000251
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RIESGO
abrir
ReferênciaVexDay Proof
Total Video Player 1.03 - '.m3u' File Local Buffer Overflow
CVE-2007-0949localwindows
Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers t
28RIESGO
abrir
Referência
CVE-2017-6971
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RIESGO
abrir
Referência
PHPJabbers Appointment Scheduler 2.3 - Reflected XSS (Cross-Site Scripting)
CVE-2020-35416webappsphp
Multiple cross-site scripting (XSS) vulnerabilities exist in PHPJabbers Appointment Scheduler 2.3, in the index.php admi
23RIESGO
abrir
Referência
CVE-2010-1953
Directory traversal vulnerability in the iNetLanka Multiple Map (com_multimap) component 1.0 for Joomla! allows remote a
43RIESGO
abrir
Referência
CVE-2010-1471
Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attacke
43RIESGO
abrir
Referência
CVE-2010-1471
Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attacke
43RIESGO
abrir
Referência
CVE-2010-4335
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows re
50RIESGO
abrir
Referência
CVE-2013-1603
An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DC
28RIESGO
abrir
Referência
CVE-2017-7981
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project W
28RIESGO
abrir
Referência
CVE-2018-1041
A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an e
28RIESGO
abrir
Referência
CVE-2010-4335
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows re
50RIESGO
abrir
Referência
CVE-2010-1929
Multiple stack-based buffer overflows in the jclient._Java_novell_jclient_JClient_defineClass@20 function in jclient.dll
28RIESGO
abrir
Referência
CVE-2013-7137
The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and
28RIESGO
abrir
ReferênciaVexDay Proof
XnView 1.93.6 - '.taac' Local Buffer Overflow
CVE-2008-2427localwindows
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD a
28RIESGO
abrir
ReferênciaVexDay Proof
ImageStation - 'SonyISUpload.cab 1.0.0.38' ActiveX Buffer Overflow (PoC)
CVE-2008-0748doswindows
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RIESGO
abrir
Referência
CVE-2017-14016
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati
43RIESGO
abrir
Referência
CVE-2018-15442
Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61RIESGO
abrir
Referência
CVE-2018-15442
Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61RIESGO
abrir
Referência
CVE-2014-0787
WellinTech KingSCADA Stack-based Buffer Overflow
53RIESGO
abrir
ReferênciaVexDay Proof
RiteCMS 2.2.1 - Authenticated Remote Code Execution
CVE-2020-23934webappsphp
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php
28RIESGO
abrir
Referência
CVE-2017-12785
The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on Novi
28RIESGO
abrir
Referência
CVE-2020-28351
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a r
43RIESGO
abrir
Referência
CVE-2020-35606
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex
28RIESGO
abrir
Referência
CVE-2019-9491
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RIESGO
abrir
Referência
CVE-2017-0060
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
28RIESGO
abrir
Referência
CVE-2020-0986
CVE-2020-0986HIGHbajo ataque
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
76RIESGO
abrir
Referência
CVE-2018-11311
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack
28RIESGO
abrir
Referência
CVE-2022-31125
Authentication Bypass in Roxy-wi
53RIESGO
abrir
Referência
CVE-2020-23935
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (
28RIESGO
abrir
anteriorpágina 260 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.