Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
22.910 exploits
Referência
CVE-2021-44848
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RIESGO
abrir
ReferênciaVexDay Proof
OpenImpro 1.1 - 'image.php' SQL Injection
CVE-2008-3599webappsphp
SQL injection vulnerability in image.php in OpenImpro 1.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Yahoo! Messenger Webcam 8.1 - ActiveX Remote Buffer Overflow
CVE-2007-3147remotewindows
Buffer overflow in the Yahoo! Webcam Upload ActiveX control in ywcupl.dll 2.0.1.4 for Yahoo! Messenger 8.1.0.249 allows
50RIESGO
abrir
ReferênciaVexDay Proof
Userlocator 3.0 - Blind SQL Injection
CVE-2008-5863webappsphp
SQL injection vulnerability in locator.php in the Userlocator module 3.0 for Woltlab Burning Board (wBB) allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
BlogHelper - Remote Configuration File Disclosure
CVE-2009-0826webappsphp
BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to do
23RIESGO
abrir
Referência
CVE-2012-4891
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers t
23RIESGO
abrir
Referência
CVE-2019-7256
CVE-2019-7256CRITICALbajo ataque
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir
ReferênciaVexDay Proof
Quicksilver Forums 1.4.1 - SQL Injection
CVE-2008-3601webappsphp
SQL injection vulnerability in index.php in Quicksilver Forums 1.4.1 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
Vacation Rental Script 3.0 - 'id' SQL Injection
CVE-2008-3603webappsphp
SQL injection vulnerability in index.php in Vacation Rental Script 3.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2019-7276
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RIESGO
abrir
Referência
CVE-2014-5073
vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands
60RIESGO
abrir
Referência
snapd < 2.37 (Ubuntu) - 'dirty_sock' Local Privilege Escalation (1)
CVE-2019-7304HIGHlocallinux
Local privilege escalation via snapd socket
53RIESGO
abrir
Referência
snapd < 2.37 (Ubuntu) - 'dirty_sock' Local Privilege Escalation (2)
CVE-2019-7304HIGHlocallinux
Local privilege escalation via snapd socket
53RIESGO
abrir
Referência
CVE-2021-45092
Thinfinity VirtualUI before 3.0 has functionality in /lab.html reachable by default that could allow IFRAME injection vi
50RIESGO
abrir
Referência
CVE-2018-0824
CVE-2018-0824HIGHbajo ataque
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RIESGO
abrir
ReferênciaVexDay Proof
GDL 4.x - 'node' SQL Injection
CVE-2009-0965webappsphp
SQL injection vulnerability in functions/browse.php in Ganesha Digital Library (GDL) 4.0 and 4.2 allows remote attackers
23RIESGO
abrir
Referência
CVE-2021-46379
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrust
43RIESGO
abrir
Referência
CVE-2021-40449
CVE-2021-40449HIGHbajo ataqueransomware
Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Referência
CVE-2019-7440
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
23RIESGO
abrir
Referência
CVE-2016-7202
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute a
45RIESGO
abrir
Referência
CVE-2016-7202
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute a
45RIESGO
abrir
Referência
CVE-2014-7868
Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT
45RIESGO
abrir
Referência
CVE-2017-1000028
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir
Referência
CVE-2017-17560
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquer
60RIESGO
abrir
Referência
CVE-2019-7440
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
23RIESGO
abrir
Referência
CVE-2021-46422
Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute
60RIESGO
abrir
Referência
CVE-2011-0762
The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a deni
60RIESGO
abrir
Referência
CVE-2011-5007
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB
60RIESGO
abrir
Referência
CVE-2014-9618
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att
60RIESGO
abrir
Referência
CVE-2014-9618
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote att
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.