Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.270 exploits
Exploit-DB✓ VexDay Proof
Telaen 2.7.x - Cross-Site Scripting
Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Telaen 2.7.x - Open Redirection
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victim
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Telaen - Information Disclosure
Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RIESGO
abrir ↗Metasploit300
HP Data Protector Cell Request Service Buffer Overflow
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arb
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT/2000/2003/2008/XP/Vista/7/8 - 'EPATHOBJ' Local Ring
20RIESGO
abrir ↗Exploit-DB
ModSecurity - Remote Null Pointer Dereference
The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NUL
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lianja SQL 1.0.0RC5.1 - db_netserver Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a de
50RIESGO
abrir ↗GitHub PoC★ 2
Novell ZENworks Mobile Management - LFI RCE
Directory traversal vulnerability in MDM.php in Novell ZENworks Mobile Management (ZMM) 2.6.1 and 2.7.0 allows remote at
50RIESGO
abrir ↗Exploit-DB
Monkey HTTPd 1.1.1 - Crash (PoC)
The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of serv
28RIESGO
abrir ↗Metasploit300
Monkey HTTPD Header Parsing Denial of Service (DoS)
Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) be
23RIESGO
abrir ↗Metasploit0
Intrasrv 1.0 Buffer Overflow
A remote SEH buffer overflow has been discovered in IntraSrv 1.0 (2007-06-03). An attacker may send a crafted HTTP GET o
30RIESGO
abrir ↗Metasploit300
Synactis PDF In-The-Box ConnectToSynactic Stack Buffer Overflow
Synactis PDF In-The-Box ConnectToSynactic Stack-Based Buffer Overflow
36RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is dis
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TP-Link IP Cameras Firmware 1.6.18P12 - Multiple Vulnerabilities
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cam
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MayGion IP Cameras Firmware 09.27 - Multiple Vulnerabilities
Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitra
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM SPSS SamplePower C1Tab - ActiveX Heap Overflow (Metasploit)
Buffer overflow in the c1sizer ActiveX control in C1sizer.ocx in IBM SPSS SamplePower 3.0 before FP1 allows remote attac
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to t
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MayGion IP Cameras Firmware 09.27 - Multiple Vulnerabilities
Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zavio IP Cameras Firmware 1.6.03 - Multiple Vulnerabilities
An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TP-Link IP Cameras Firmware 1.6.18P12 - Multiple Vulnerabilities
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 d
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nginx 1.3.9 < 1.4.0 - Chuncked Encoding Stack Buffer Overflow (Metasploit)
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir ↗Exploit-DB
RadioCMS 2.2 - 'menager.php?playlist_id' SQL Injection
SQL injection vulnerability in meneger.php in RadioCMS 2.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AdobeCollabSync - Local Buffer Overflow / Adobe Reader X Sandbox Bypass (Metasploit)
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attacke
60RIESGO
abrir ↗Metasploit500
Apache Struts includeParams Remote Code Execution
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not
60RIESGO
abrir ↗Metasploit500
Apache Struts includeParams Remote Code Execution
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not
60RIESGO
abrir ↗Metasploit300
ERS Viewer 2013 ERS File Handling Buffer Overflow
Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.
50RIESGO
abrir ↗Metasploit200
Novell Client 2 SP3 nicm.sys Local Privilege Escalation
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.