Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.836exploits catalogados
35.811CVEs con explotación pública
24.695probados en laboratorio
22.549 exploits
ReferênciaVexDay Proof
ChilkatHttp ActiveX 2.3 - Arbitrary Files Overwrite
CVE-2008-1647remotewindows
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0,
23RIESGO
abrir
Referência
CVE-2015-6763
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service o
23RIESGO
abrir
Referência
CVE-2015-6763
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service o
23RIESGO
abrir
Referência
CVE-2021-22146
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
28RIESGO
abrir
Referência
CVE-2010-0677
SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers
23RIESGO
abrir
Referência
CVE-2015-2518
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir
Referência
CVE-2015-2511
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir
ReferênciaVexDay Proof
X10media Mp3 Search Engine 1.6 - Remote File Disclosure
CVE-2008-6960webappsphp
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitr
23RIESGO
abrir
Referência
CVE-2010-4301
epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers t
23RIESGO
abrir
Referência
CVE-2013-4859
INSTEON Hub 2242-222 lacks Web and API authentication
23RIESGO
abrir
Referência
CVE-2017-15270
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) f
23RIESGO
abrir
Referência
CVE-2017-15270
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) f
23RIESGO
abrir
Referência
CVE-2019-1914
Cisco Small Business 220 Series Smart Switches Command Injection Vulnerability
46RIESGO
abrir
Referência
CVE-2015-8358
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators t
23RIESGO
abrir
Referência
CVE-2015-8358
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators t
23RIESGO
abrir
Referência
CVE-2017-2363
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir
Referência
CVE-2014-3008
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacte
23RIESGO
abrir
Referência
CVE-2017-3316
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions tha
23RIESGO
abrir
Referência
CVE-2013-2121
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote
43RIESGO
abrir
Referência
CVE-2017-2932
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript
28RIESGO
abrir
ReferênciaVexDay Proof
Active PHP Bookmark Notes 0.2.5 - Remote File Inclusion
CVE-2007-1621webappsphp
PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allow
23RIESGO
abrir
Referência
CVE-2010-4968
SQL injection vulnerability in the webmaster-tips.net Flash Gallery (com_wmtpic) component 1.0 for Joomla! allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Clever Internet ActiveX Suite 6.2 - Arbitrary File Download/Overwrite
CVE-2007-4067remotewindows
Absolute path traversal vulnerability in the clInetSuiteX6.clWebDav ActiveX control in CLINETSUITEX6.OCX in Clever Inter
23RIESGO
abrir
Referência
CVE-2010-4972
SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
ExBB 0.22 - Local/Remote File Inclusion
CVE-2008-1861webappsphp
Directory traversal vulnerability in modules/threadstop/threadstop.php in ExBB Italia 0.22 and earlier, when register_gl
23RIESGO
abrir
Referência
CVE-2015-4683
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potenti
23RIESGO
abrir
Referência
CVE-2015-4683
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potenti
23RIESGO
abrir
Referência
CVE-2021-22204
CVE-2021-22204MEDIUMbajo ataque
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir
Referência
CVE-2017-2466
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Referência
CVE-2013-4103
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
23RIESGO
abrir
anteriorpágina 566 / 752siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.