Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.408exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.608VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
81.409 exploits
Exploit-DB✓ VexDay Proof
IBM Lotus Notes Client URL Handler - Command Injection (Metasploit)
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted
50RIESGO
abrir ↗Metasploit200
Nvidia (nvsvc) Display Driver Service Local Privilege Escalation
The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TWiki MAKETEXT - Remote Command Execution (Metasploit)
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foswiki MAKETEXT - Remote Command Execution (Metasploit)
The localization functionality in TWiki before 5.1.3, and Foswiki 1.0.x through 1.0.10 and 1.1.x through 1.1.6, allows r
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foswiki MAKETEXT - Remote Command Execution (Metasploit)
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android 4.2 Browser and WebView - 'addJavascriptInterface' Code Execution (Metasploit)
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android 4.2 Browser and WebView - 'addJavascriptInterface' Code Execution (Metasploit)
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Elite Bulletin Board 2.1.21 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the (1) update_whosonline_reg and (2) update_whosonline_guest functions in Eli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information v
23RIESGO
abrir ↗Exploit-DB
FireFly Mediaserver 1.0.0.1359 - Null Pointer Dereference
Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1
28RIESGO
abrir ↗Metasploit600
Android Browser and WebView addJavascriptInterface Code Execution
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RIESGO
abrir ↗Metasploit600
Android Browser and WebView addJavascriptInterface Code Execution
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
banana dance b.2.6 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Banana Dance B.2.6 and earlier allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
InduSoft Web Studio - 'ISSymbol.ocx InternationalSeparator()' Heap Overflow (Metasploit)
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol v
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Crystal Reports CrystalPrintControl - ActiveX ServerResourceVersion Property Overflow (Metasploit)
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPWCMS 1.5.4.6 - 'preg_replace' Multiple Vulnerabilities
IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands.
23RIESGO
abrir ↗Metasploit600
TWiki MAKETEXT Remote Command Execution
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RIESGO
abrir ↗Metasploit300
RealPlayer RealMedia File Handling Buffer Overflow
Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers
50RIESGO
abrir ↗Exploit-DB
Cisco Wireless Lan Controller 7.2.110.0 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Wireless LAN Controller (WLC) devices with software
23RIESGO
abrir ↗Exploit-DB
Cisco Wireless Lan Controller 7.2.110.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) dev
23RIESGO
abrir ↗Exploit-DB
Centreon Enterprise Server 2.3.3 < 2.3.9-4 - Blind SQL Injection
SQL injection vulnerability in menuXML.php in Centreon 2.3.3 through 2.3.9-4 (fixed in Centreon web 2.6.0) allows remote
23RIESGO
abrir ↗Exploit-DB
Cisco Wireless Lan Controller 7.2.110.0 - Multiple Vulnerabilities
screens/base/web_auth_custom.html on Cisco Wireless LAN Controller (WLC) devices with software 7.2.110.0 allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.3.5 - Btrfs CRC32C feature Infinite Loop Local Denial of Service
The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Portable phpMyAdmin - Authentication Bypass
The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain ph
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbi
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrar
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent - XML Parsing Remote Code Execution
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RIESGO
abrir ↗Exploit-DB
Axway Secure Transport 5.1 SP2 - Directory Traversal
Multiple directory traversal vulnerabilities in Axway SecureTransport 5.1 SP2 and earlier allow remote authenticated use
23RIESGO
abrir ↗Metasploit300
Novell eDirectory 8 Buffer Overflow
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote at
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.