Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.439exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.639VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
81.439 exploits
Exploit-DB✓ VexDay Proof
(SSH.com Communications) SSH Tectia (SSH < 2.0-6.1.9.95 / Tectia 6.1.9.95) - Remote Authentication Bypass
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6
50RIESGO
abrir ↗Exploit-DB
MySQL - Denial of Service (PoC)
Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote a
28RIESGO
abrir ↗Exploit-DB
IBM System Director Agent - Remote System Level
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
freeFTPd 1.2.6 - Remote Authentication Bypass
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RIESGO
abrir ↗Metasploit600
Oracle MySQL for Microsoft Windows FILE Privilege Abuse
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗Metasploit600
Oracle MySQL for Microsoft Windows MOF Execution
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗Metasploit300
Android Stock Browser Iframe DOS
The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a
18RIESGO
abrir ↗Metasploit600
Tectia SSH USERAUTH Change Request Password Reset Vulnerability
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6
50RIESGO
abrir ↗Metasploit300
Symantec Messaging Gateway 9.5 Log File Download Vulnerability
Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow r
50RIESGO
abrir ↗Metasploit600
Nagios XI Network Monitor Graph Explorer Component Command Injection
Nagios XI Network Monitor Graph Explorer Component < 1.3 Authenticated Command Injection
36RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Video Lead Form - 'errMsg' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Elastix - 'page' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7.7.2 - MIME Type Buffer Overflow (Metasploit)
Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause
50RIESGO
abrir ↗Metasploit600
MS13-005 HWND_BROADCAST Low to Medium Integrity Privilege Escalation
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7
43RIESGO
abrir ↗Metasploit600
Maxthon3 about:history XCS Trusted Zone Code Execution
Maxthon3 about:history XCS Trusted Zone Code Execution
36RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mcrypt 2.6.8 - Stack Buffer Overflow (PoC)
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Forescout CounterACT - 'a' Open Redirection
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mcrypt 2.5.8 - Local Stack Overflow
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7.7.2 - TeXML Style Element font-table Field Stack Buffer Overflow (Metasploit)
Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a de
50RIESGO
abrir ↗Exploit-DB
TrouSerS - Denial of Service
tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_of
28RIESGO
abrir ↗Exploit-DB
lighttpd 1.4.31 - Denial of Service (PoC)
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial o
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetIQ Privileged User Manager 2.3.1 - 'ldapagnt_eval()' Perl Remote Code Execution (Metasploit)
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manage
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
dotProject 2.1.x - 'index.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
dotProject 2.1.x - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrar
23RIESGO
abrir ↗Metasploit300
CUPS 1.6.1 Root File Read
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator
18RIESGO
abrir ↗Metasploit300
KingView Log File Parsing Buffer Overflow
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView
50RIESGO
abrir ↗Exploit-DB
Apple QuickTime 7.7.2 - Targa image Buffer Overflow
Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of s
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell File Reporter (NFR) Agent FSFUI Record - Arbitrary File Upload / Remote Code Execution (Metasploit)
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RIESGO
abrir ↗Metasploit300
NFR Agent SRS Record Arbitrary Remote File Access
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbi
50RIESGO
abrir ↗Metasploit300
NFR Agent FSFUI Record Arbitrary Remote File Access
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrar
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.