Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
21.797 exploits
Referência
CVE-2016-4230
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
ReferênciaVexDay Proof
Oracle 10g - MDSYS.SDO_TOPO_DROP_FTBL SQL Injection (Metasploit)
CVE-2008-3979localmultiple
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authent
50RIESGO
abrir
ReferênciaVexDay Proof
Konqueror 3.5.9 - 'font color' Remote Crash
CVE-2008-4514doslinux
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a fo
23RIESGO
abrir
Referência
CVE-2014-5084
A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let
23RIESGO
abrir
Referência
CVE-2012-4889
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inje
38RIESGO
abrir
Referência
CVE-2017-0245
The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local
23RIESGO
abrir
Referência
CVE-2021-21551
CVE-2021-21551HIGHbajo ataque
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
98RIESGO
abrir
Referência
CVE-2009-3250
The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated u
28RIESGO
abrir
Referência
CVE-2020-14946
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and e
23RIESGO
abrir
Referência
CVE-2020-12351
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RIESGO
abrir
Referência
CVE-2017-0569
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execu
23RIESGO
abrir
Referência
CVE-2021-44665
A Directory Traversal vulnerability exists in the Xerte Project Xerte through 3.10.3 when downloading a project file via
23RIESGO
abrir
Referência
CVE-2023-34634
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green
38RIESGO
abrir
Referência
CVE-2023-34634
Greenshot 1.2.10 and below allows arbitrary code execution because .NET content is insecurely deserialized when a .green
38RIESGO
abrir
Referência
CVE-2006-4842
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RIESGO
abrir
ReferênciaVexDay Proof
bugmall shopping cart 2.5 - SQL Injection / Cross-Site Scripting
CVE-2007-3446webappsphp
BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Wp-FileManager 1.2 - Arbitrary File Upload
CVE-2008-0222webappsphp
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
Titan FTP Server 6.03 - 'USER/PASS' Remote Heap Overflow (PoC)
CVE-2008-0702doswindows
Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of
38RIESGO
abrir
ReferênciaVexDay Proof
Panda Security ActiveScan 2.0 (Update) - Remote Buffer Overflow
CVE-2008-3155remotewindows
Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attac
23RIESGO
abrir
Referência
Virtual Reception v1.0 - Web Server Directory Traversal
CVE-2023-25289HIGHwebappsmultiple
Directory Traversal vulnerability in virtualreception Digital Receptie version win7sp1_rtm.101119-1850 6.1.7601.1.0.6579
41RIESGO
abrir
Referência
CVE-2014-3085
systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote auth
23RIESGO
abrir
Referência
CVE-2014-3085
systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote auth
23RIESGO
abrir
Referência
CVE-2015-0514
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-cen
23RIESGO
abrir
Referência
CVE-2009-5067
Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a .. (dot
23RIESGO
abrir
Referência
CVE-2014-3740
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbi
23RIESGO
abrir
Referência
CVE-2016-7185
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RIESGO
abrir
Referência
CVE-2011-2963
TCPUploadServer.exe in Progea Movicon 11.2 before Build 1084 does not require authentication for critical functions, whi
23RIESGO
abrir
Referência
CVE-2014-4306
Directory traversal vulnerability in logs-x.php in WebTitan before 4.04 allows remote attackers to read arbitrary files
23RIESGO
abrir
Referência
CVE-2013-1807
PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web docu
23RIESGO
abrir
Referência
CVE-2018-18955
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RIESGO
abrir
anteriorpágina 305 / 727siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.