Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9136Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
81.524 exploits
Exploit-DB✓ VexDay Proof
Splunk - Remote Command Execution
Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Splunk - Remote Command Execution
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Splunk - Remote Command Execution
Splunk 4.2.5 and earlier, when a Free license is selected, enables potentially undesirable functionality within an envir
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BrowserCRM 5.100.1 - 'parent_id' SQL Injection
Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BrowserCRM 5.100.1 - 'contact_id' SQL Injection
Multiple SQL injection vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BrowserCRM 5.100.1 - 'login[]' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BrowserCRM 5.100.1 - URI Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pulse Pro 1.7.2 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BrowserCRM 5.100.1 - 'framed' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BrowserCRM 5.100.1 - 'clients.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in BrowserCRM 5.100.01 and earlier allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PmWiki 2.2.34 - 'pagelist' Remote PHP Code Injection (2) (Metasploit)
The PageListSort function in scripts/pagelist.php in PmWiki 2.x before 2.2.35 allows remote attackers to execute arbitra
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CoDeSys SCADA 2.3 - WebServer Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB
60RIESGO
abrir ↗Metasploit300
MS11-093 Microsoft Windows OLE Object File Handling Remote Code Execution
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote a
60RIESGO
abrir ↗Metasploit300
IpSwitch WhatsUp Gold TFTP Directory Traversal
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read a
50RIESGO
abrir ↗Metasploit600
Traq admincp/common.php Remote Code Execution
Traq 2.0–2.3 admincp/common.php RCE
63RIESGO
abrir ↗Metasploit600
Splunk Search Remote Code Execution
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera Web Browser < 11.60 - Denial of Service / Multiple Vulnerabilities
Opera before 11.60 does not properly handle certificate revocation, which has unspecified impact and remote attack vecto
23RIESGO
abrir ↗Exploit-DB
zFTPServer Suite 6.0.0.52 - 'rmdir' Directory Traversal
Directory traversal vulnerability in zFTPServer Suite 6.0.0.52 allows remote authenticated users to delete arbitrary dir
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Family CMS 2.7.2 - Multiple Persistent Cross-Site Scripting Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow re
23RIESGO
abrir ↗Exploit-DB
Acpid 1:2.0.10-1ubuntu2 (Ubuntu 11.04/11.10) - Boundary Crossing Privilege Escalation
samples/powerbtn/powerbtn.sh in acpid (aka acpid2) 2.0.16 and earlier uses the pidof program incorrectly, which allows l
23RIESGO
abrir ↗Exploit-DB
Apache - Denial of Service
GIGAPOD file servers (Appliance model and Software model) provide two web interfaces, 80/tcp and 443/tcp for user operat
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Docebo Lms 4.0.4 - 'Messages' Remote Code Execution
Multiple SQL injection vulnerabilities in the save_connection function in lib/lib.iotask.php in the iotask module in Doc
23RIESGO
abrir ↗Exploit-DB
CSF Firewall - Buffer Overflow (PoC)
Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CyberLink (Multiple Products) - File Project Handling Stack Buffer Overflow (PoC)
Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to e
50RIESGO
abrir ↗Exploit-DB
Apache - Denial of Service
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HomeSeer HS2 2.5.0.20 - Web Interface Log Viewer Page URI Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Application Lifestyle Management 11 - 'GetInstalledPackages' Local Privilege Escalation
The GetInstalledPackages function in the configuration tool in HP Application Lifestyle Management (ALM) 11 on AIX, HP-U
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Family Connections CMS 2.7.1 - 'less.php' Remote Command Execution (Metasploit)
dev/less.php in Family Connections CMS (FCMS) 2.5.0 - 2.7.1, when register_globals is enabled, allows remote attackers t
50RIESGO
abrir ↗Metasploit400
TrendMicro Control Manger CmdProcessor.exe Stack Buffer Overflow
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcess
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.