Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.523 exploits
Referência
CVE-2018-7653
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
38RIESGO
abrir ↗Referência
CVE-2009-4991
Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2015-7894
The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow
23RIESGO
abrir ↗Referência
CVE-2009-2533
rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of
23RIESGO
abrir ↗Referência
CVE-2017-17058
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RIESGO
abrir ↗Referência
CVE-2017-17058
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RIESGO
abrir ↗Referência
CVE-2013-1599
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm
35RIESGO
abrir ↗Referência
CVE-2017-4914
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of th
23RIESGO
abrir ↗Referência
CVE-2013-1599
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm
35RIESGO
abrir ↗Referência
CVE-2017-10309
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affecte
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPStore Car Dealers - Arbitrary File Upload
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitra
23RIESGO
abrir ↗Referência
CVE-2013-1606
Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allow
28RIESGO
abrir ↗Referência✓ VexDay Proof
WOW Web On Windows ActiveX Control 2 - Remote Code Execution
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attac
23RIESGO
abrir ↗Referência
CVE-2015-8357
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RIESGO
abrir ↗Referência
CVE-2010-4051
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows c
35RIESGO
abrir ↗Referência
CVE-2015-8357
Directory traversal vulnerability in the bitrix.xscan module before 1.0.4 for Bitrix allows remote authenticated users t
23RIESGO
abrir ↗Referência
CVE-2012-5329
Buffer overflow in TYPSoft FTP Server 1.1 allows remote authenticated users to cause a denial of service (application cr
23RIESGO
abrir ↗Referência
CVE-2017-8311
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mozilla Firefox 3.0.10 - 'KEYGEN' Remote Denial of Service
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebYep 1.1.9 - 'webyep_sIncludePath' File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow (PoC)
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RIESGO
abrir ↗Referência✓ VexDay Proof
MangoBery CMS 0.5.5 - 'quotes.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
LeadTools Raster - Dialog File_D Object Remote Buffer Overflow (PoC)
Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
HP Digital Imaging 'hpqxml.dll 2.0.0.133' - Arbitrary Data Write
Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imagi
23RIESGO
abrir ↗Referência
CVE-2010-4181
Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslas
23RIESGO
abrir ↗Referência
CVE-2009-3710
RioRey RIOS 4.6.6 and 4.7.0 uses an undocumented, hard-coded username (dbadmin) and password (sq!us3r) for an SSH tunnel
23RIESGO
abrir ↗Referência
CVE-2019-15943
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or de
23RIESGO
abrir ↗Referência
CVE-2014-8826
LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypas
23RIESGO
abrir ↗Referência
CVE-2018-7736
In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the so
23RIESGO
abrir ↗Referência
CVE-2018-7736
In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the so
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.