Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.207exploits catalogados
36.419CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 23.022GitHub PoC 15.023VulnCheck XDB 8846Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Prizm Content Connect - Arbitrary File Upload
Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung Kies - Remote Buffer Overflow
Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Cognos - 'tm1admsd.exe' Remote Overflow (Metasploit)
Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Google Document Embedder - Arbitrary File Disclosure (Metasploit)
Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers t
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox < 17.0.1 - Flash Privileged Code Injection (Metasploit)
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderb
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox < 17.0.1 - Flash Privileged Code Injection (Metasploit)
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbi
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Movable Type 4.2x/4.3x - Web Upgrade Remote Code Execution (Metasploit)
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Movable Type 4.2x/4.3x - Web Upgrade Remote Code Execution (Metasploit)
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for reque
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nexpose Security Console - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Havalite CMS - 'comment' HTML Injection
Havalite CMS 1.1.7 has a stored XSS vulnerability
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Enterasys NetSight - 'nssyslogd.exe' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Belkin Wireless Router - Default WPS PIN Security
Belkin wireless routers Surf N150 Model F7D1301v1, N900 Model F9K1104v1, N450 Model F9K1105V2, and N300 Model F7D2301v1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
e107 1.0.2 - SQL Injection (via Cross-Site Request Forgery)
Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CButton Object Use-After-Free (Metasploit)
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
e107 1.0.1 - Arbitrary JavaScript Execution (via Cross-Site Request Forgery)
Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hija
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus QuickR qp2 - ActiveX Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-00
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BlazeDVD 6.1 - '.PLF' File (ASLR + DEP Bypass) (Metasploit)
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus iNotes dwa85W - ActiveX Buffer Overflow (Metasploit)
Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x befo
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Grep < 2.11 - Integer Overflow Crash (PoC)
Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CDwnBindInfo Object Use-After-Free (Metasploit)
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RealPlayer - '.RealMedia' File Handling Buffer Overflow (Metasploit)
Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus Notes Client URL Handler - Command Injection (Metasploit)
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foswiki MAKETEXT - Remote Command Execution (Metasploit)
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows r
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TWiki MAKETEXT - Remote Command Execution (Metasploit)
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foswiki MAKETEXT - Remote Command Execution (Metasploit)
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android 4.2 Browser and WebView - 'addJavascriptInterface' Code Execution (Metasploit)
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Elite Bulletin Board 2.1.21 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Eli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android 4.2 Browser and WebView - 'addJavascriptInterface' Code Execution (Metasploit)
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.