Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.542VulnCheck XDB 9091Nuclei 4434Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.192 exploits
Exploit-DB✓ VexDay Proof
VMware vCenter - Chargeback Manager ImageUploadServlet Arbitrary File Upload (Metasploit)
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers t
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XnView 2.03 - '.pct' Buffer Overflow
Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
28RIESGO
abrir ↗Exploit-DB
Samsung PS50C7700 TV - Denial of Service
The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon cras
23RIESGO
abrir ↗Exploit-DB
Microsoft DirectShow - Arbitrary Memory Overwrite (MS13-056)
DirectShow in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foreman (RedHat OpenStack/Satellite) - bookmarks/create Code Injection (Metasploit)
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7 - Invalid Atom Length Buffer Overflow (Metasploit)
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of s
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PCMan FTP Server 2.0.7 - Remote (Metasploit)
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Managed Printing Administration - jobAcct Remote Command Execution (Metasploit)
Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Anchor CMS 0.9.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote at
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows Movie Maker 2.1.4026.0 - '.wav' Crash (PoC)
Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (applica
28RIESGO
abrir ↗Exploit-DB
Xibo 1.2.2/1.4.1 - 'index.php?p' Directory Traversal
Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attacke
43RIESGO
abrir ↗Exploit-DB
Microsoft Windows Movie Maker 2.1.4026.0 - '.wav' Crash (PoC)
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RIESGO
abrir ↗Exploit-DB
Symantec Workspace Virtualization 6.4.1895.0 - Kernel Mode Privilege Escalation
Symantec Workspace Virtualization before 6.x before 6.4.1953.0, when a virtual application layer is configured, allows l
23RIESGO
abrir ↗VulnCheck XDB
local
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain
71RIESGO
abrir ↗GitHub PoC★ 5
CVE-2013-2596 exploit for android
Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain
71RIESGO
abrir ↗Metasploit600
Oracle Endeca Server Remote Command Execution
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows rem
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BlazeDVD Pro Player 6.1 - Direct RET Local Stack Buffer Overflow
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Squid 3.3.5 - Denial of Service (PoC)
client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts 2.2.3 - Multiple Open Redirections
Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to
60RIESGO
abrir ↗Exploit-DB
rpcbind - CALLIT procedure UDP Crash (PoC)
The svc_dg_getargs function in libtirpc 0.2.3 and earlier allows remote attackers to cause a denial of service (rpcbind
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ReadyMedia - Remote Heap Buffer Overflow
MiniDLNA has heap-based buffer overflow
23RIESGO
abrir ↗Exploit-DB
McAfee ePO 4.6.6 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Corel PDF Fusion - Local Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Corel PDF Fusion - Local Stack Buffer Overflow (Metasploit)
Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wi
43RIESGO
abrir ↗Exploit-DB
BMC Service Desk Express 10.2.1.95 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB
McAfee ePO 4.6.6 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extens
23RIESGO
abrir ↗Exploit-DB
Tri-PLC Nano-10 r81 - Denial of Service
Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bo
23RIESGO
abrir ↗Exploit-DB
BMC Service Desk Express 10.2.1.95 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Pie Register - 'wp-login.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before
23RIESGO
abrir ↗Metasploit600
Linksys Devices pingstr Remote Command Injection
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentica
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.