Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.866exploits catalogados
35.812CVEs con explotación pública
24.695probados en laboratorio
22.549 exploits
Referência
CVE-2010-1050
SQL injection vulnerability in index.php in AudiStat 1.3 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2009-4761
Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir
Referência
CVE-2010-2348
Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2024-3673
Web Directory Free < 1.7.3 - Unauthenticated LFI
63RIESGO
abrir
Referência
Adiscon LogAnalyzer v.4.1.13 - Cross Site Scripting
CVE-2023-36306webappsphp
A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to exec
38RIESGO
abrir
Referência
CVE-2010-1533
Directory traversal vulnerability in the TweetLA (com_tweetla) component 1.0.1 for Joomla! allows remote attackers to re
43RIESGO
abrir
Referência
CVE-2013-1602
An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP ses
28RIESGO
abrir
Referência
CVE-2010-3140
Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local
28RIESGO
abrir
ReferênciaVexDay Proof
Multi-Threaded TFTP 1.1 - GET Denial of Service
CVE-2006-4781doswindows
Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of
23RIESGO
abrir
Referência
CVE-2014-10078
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfa
23RIESGO
abrir
ReferênciaVexDay Proof
TotalCalendar 2.30 - 'inc' Remote File Inclusion
CVE-2006-7055webappsphp
PHP remote file inclusion vulnerability in index.php in TotalCalendar 2.30 and earlier allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
EntertainmentScript 1.4.0 - 'play.php' SQL Injection
CVE-2008-2393webappsphp
SQL injection vulnerability in play.php in EntertainmentScript 1.4.0 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Referência
CVE-2018-11505
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp
23RIESGO
abrir
Referência
CVE-2021-25680
The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These
23RIESGO
abrir
Referência
CVE-2010-1053
Multiple SQL injection vulnerabilities in Zen Time Tracking 2.2 and earlier, when magic_quotes_gpc is disabled, allow re
23RIESGO
abrir
Referência
CVE-2016-3974
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remo
28RIESGO
abrir
Referência
CVE-2016-3974
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remo
28RIESGO
abrir
Referência
CVE-2017-11319
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and c
23RIESGO
abrir
Referência
CVE-2017-11319
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and c
23RIESGO
abrir
Referência
CVE-2009-2379
Directory traversal vulnerability in public/index.php in BIGACE Web CMS 2.6 allows remote attackers to include and execu
23RIESGO
abrir
Referência
CVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled,
23RIESGO
abrir
Referência
CVE-2010-4399
Directory traversal vulnerability in languages.inc.php in DynPG CMS 4.1.1 and 4.2.0, when magic_quotes_gpc is disabled,
23RIESGO
abrir
ReferênciaVexDay Proof
MP3 TrackMaker 1.5 - '.mp3' Local Heap Overflow (PoC)
CVE-2009-0175doswindows
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (
23RIESGO
abrir
Referência
CVE-2019-7400
Rukovoditel before 2.4.1 allows XSS.
23RIESGO
abrir
Referência
CVE-2019-7400
Rukovoditel before 2.4.1 allows XSS.
23RIESGO
abrir
Referência
CVE-2017-16543
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated
23RIESGO
abrir
Referência
CVE-2012-6307
A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious
23RIESGO
abrir
ReferênciaVexDay Proof
TLS - Renegotiation
CVE-2009-3555CRITICALremotemultiple
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RIESGO
abrir
Referência
CVE-2019-25706
Across DR-810 ROM-0 Unauthenticated File Disclosure
41RIESGO
abrir
Referência
CVE-2014-0866
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext c
23RIESGO
abrir
anteriorpágina 572 / 752siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.