Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.064 exploits
Exploit-DB
Oracle Forms and Reports 11.1 - Arbitrary Code Execution
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RIESGO
abrir ↗Exploit-DB
Oracle Forms and Reports 11.1 - Arbitrary Code Execution
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PCMan FTP Server 2.07 - 'CWD' Remote Buffer Overflow
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗Exploit-DB
ManageEngine Support Center Plus 7916 - Directory Traversal
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arb
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Eventum 2.3.4 - 'hostname' Remote Code Execution
htdocs/setup/index.php in Eventum before 2.3.5 allows remote attackers to inject and execute arbitrary PHP code via the
28RIESGO
abrir ↗Metasploit0
Kloxo SQL Injection and Remote Code Execution
Kloxo < 6.1.12 Unauthenticated SQL Injection RCE
43RIESGO
abrir ↗Metasploit600
SkyBlueCanvas CMS Remote Code Execution
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RIESGO
abrir ↗Metasploit300
A10 Networks AX Loadbalancer Directory Traversal
A10 Networks AX Loadbalancer Path Traversal
36RIESGO
abrir ↗GitHub PoC★ 8
Automated exploit for CVE-2012-3153 / CVE-2012-3152
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir ↗Metasploit600
MediaWiki Thumb.php Remote Command Execution
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RIESGO
abrir ↗Metasploit300
ManageEngine Support Center Plus Directory Traversal
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arb
50RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Eventum - Insecure File Permissions
Eventum before 2.3.5 allows remote attackers to reinstall the application via direct request to /setup/index.php.
23RIESGO
abrir ↗Exploit-DB
Oracle Outside In MDB - File Parsing Stack Buffer Overflow (PoC)
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.4.1 allo
23RIESGO
abrir ↗Exploit-DB
Mozilla Thunderbird 17.0.6 - Input Validation Filter Bypass
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MP3Info 0.8.5a - Buffer Overflow
Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if
23RIESGO
abrir ↗Exploit-DB
Ammyy Admin 3.2 - Authentication Bypass
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assiste
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Daum Game 1.1.0.5 - ActiveX 'IconCreate Method' Remote Stack Buffer Overflow
Buffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password fo
23RIESGO
abrir ↗Exploit-DB
MW6 Technologies MaxiCode - ActiveX 'Data' Buffer Overflow (PoC)
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RIESGO
abrir ↗Exploit-DB
MW6 Technologies Datamatrix - ActiveX 'Data' Buffer Overflow
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector - Backup Client Service Directory Traversal (Metasploit)
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Skybluecanvas CMS 1.1 r248-03 - Remote Command Execution
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RIESGO
abrir ↗Exploit-DB
MW6 Technologies Aztec - ActiveX 'Data' Buffer Overflow (PoC)
MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
41RIESGO
abrir ↗Exploit-DB
Joomla! Component JV Comment 3.0.2 - 'id' SQL Injection
SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authentic
23RIESGO
abrir ↗Exploit-DB
Joomla! Component Komento 1.7.2 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the StackIdeas Komento (com_komento) component before 1.7.3 for J
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Franklin Fueling TS-550 evo 2.0.0.6833 - Multiple Vulnerabilities
cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows
23RIESGO
abrir ↗Exploit-DB
iTechClassifieds 3.03.057 - SQL Injection
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.