Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.653VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
81.453 exploits
Exploit-DB
Subrion CMS 2.2.1 - Cross-Site Request Forgery (Add Admin)
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome for Android - Multiple 'file::' URL Handler Local Downloaded Content Disclosure Vulnerabilities
Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attack
23RIESGO
abrir ↗Exploit-DB
Ezylog Photovoltaic Management Server - Multiple Vulnerabilities
Sinapsi eSolar OS Command Injection
53RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Winamp - MAKI Buffer Overflow (Metasploit)
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome for Android - com.android.browser.application_id Intent Extra Data Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Google Chrome before 18.0.1025308 on Android allows remote attackers to inje
23RIESGO
abrir ↗Exploit-DB
Ezylog Photovoltaic Management Server - Multiple Vulnerabilities
Sinapsi eSolar Improper Authentication
48RIESGO
abrir ↗Exploit-DB
Ezylog Photovoltaic Management Server - Multiple Vulnerabilities
Sinapsi eSolar SQL Injection
41RIESGO
abrir ↗Exploit-DB
Ezylog Photovoltaic Management Server - Multiple Vulnerabilities
Sinapsi eSolar Hard-Coded Password
53RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome for Android - Same-origin Policy Bypass Local Symlink
Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome for Android - Local Application Handling Cookie Theft
Google Chrome before 18.0.1025308 on Android allows remote attackers to obtain cookie information via a crafted applicat
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
libguac - Remote Buffer Overflow
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote a
28RIESGO
abrir ↗Exploit-DB
Joomla! Component RokModule 1.1 - 'module' Blind SQL Injection
SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DELTAScripts PHP Links - Multiple SQL Injections
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DELTAScripts PHP Links - Multiple SQL Injections
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB
Joomla! Component RokModule 1.1 - 'module' Blind SQL Injection
SQL injection vulnerability in the RokModule (com_rokmodule) component 1.1 for Joomla! allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB
Oracle VM VirtualBox 4.1 - Local Denial of Service
Unspecified vulnerability in the Oracle VM Virtual Box component in Oracle Virtualization 3.2, 4.0, and 4.1 allows local
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU glibc - 'strcoll()' Routine Integer Overflow
Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-depende
28RIESGO
abrir ↗Exploit-DB
TestLink 1.9.3 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in TestLink 1.9.3 and earlier allow remote attackers to hijac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP NetWeaver Dispatcher - DiagTraceR3Info Buffer Overflow (Metasploit)
The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispa
50RIESGO
abrir ↗Metasploit300
Webmin edit_html.cgi file Parameter Traversal Arbitrary File Access
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited
23RIESGO
abrir ↗Metasploit600
Webmin /file/show.cgi Remote Command Execution
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kayako Fusion - 'download.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in __swift/thirdparty/PHPExcel/PHPExcel/Shared/JAMA/docs/download.php in Kayako
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JBoss - DeploymentFileRepository WAR Deployment (via JMXInvokerServlet) (Metasploit)
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Net-SNMP - SNMPD AgentX Subagent Timeout Denial of Service
Net-SNMP 5.7.1 and earlier, when AgentX is registering to handle a MIB and processing GETNEXT requests, allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Flogr - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Flogr 2.5.6 and earlier allow remote attackers to in
23RIESGO
abrir ↗Metasploit600
Openfiler v2.x NetworkCard Command Execution
Openfiler v2.x NetworkCard Command Execution
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ThinPrint - 'tpfc.dll' Insecure Library Loading Arbitrary Code Execution
Untrusted search path vulnerability in VMware Tools in VMware Workstation before 8.0.4, VMware Player before 4.0.4, VMwa
23RIESGO
abrir ↗Exploit-DB
Group Office Calendar - '/calendar/json.php' SQL Injection
SQL injection vulnerability in modules/calendar/json.php in Group-Office community before 4.0.90 allows remote authentic
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Photoshop CS6 - '.png' Parsing Heap Overflow
Buffer overflow in Adobe Photoshop CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafte
28RIESGO
abrir ↗Exploit-DB
OTRS Open Technology Real Services 3.1.8/3.1.9 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x befor
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.