Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9136Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
81.524 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows - TCP/IP Stack Reference Counter Integer Overflow (MS11-083)
Integer overflow in the TCP/IP implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WHMCompleteSolution 3.x/4.x - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OrderSys 1.6.4 - SQL Injection
Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Exploit-DB
Oracle - xdb.xdb_pitrig_pkg.PITRIG_DROPMETADATA procedure
Buffer overflow in the XDB.XDB_PITRIG_PKG.PITRIG_DROPMETADATA procedure in Oracle 10g R2 allows remote authenticated use
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Hyperion Strategic Finance 12.x - Tidestone Formula One WorkBook OLE Control TTF16.ocx Remote Heap Overflow
Heap-based buffer overflow in the SetDevNames method of the Tidestone Formula One ActiveX control (TTF16.ocx) 6.3.5 Buil
23RIESGO
abrir ↗Exploit-DB
KnFTP 1.0 - Remote Buffer Overflow (DEP Bypass) (Metasploit)
Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
aidiCMS 3.55 - 'ajax_create_folder.php' Remote Code Execution
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZenPhoto 1.4.1.4 - 'ajax_create_folder.php' Remote Code Execution
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Excel 2007 - '.xlb' Local Buffer Overflow (MS11-021) (Metasploit)
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain leng
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPMyFAQ 2.7.0 - 'ajax_create_folder.php' Remote Code Execution
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir ↗Metasploit600
InduSoft Web Studio Arbitrary Upload Remote Code Execution
CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require au
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Centreon 2.3.1 - 'command_name' Remote Command Execution
Directory traversal vulnerability in main.php in Merethis Centreon before 2.3.2 allows remote authenticated users to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mini-stream Ripper 3.0.1.1 - Local Buffer Overflow (Metasploit) (3)
Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long e
50RIESGO
abrir ↗Exploit-DB
DreamBox DM800 1.5rc1 - File Disclosure
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ajax File and Image Manager 1.0 Final - Remote Code Execution
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DreamBox DM800 - 'file' Local File Disclosure
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
23RIESGO
abrir ↗Exploit-DB
WHMCompleteSolution (WHMCS) 3.x - 'clientarea.php' Local File Disclosure
Directory traversal vulnerability in clientarea.php in WHMCompleteSolution (WHMCS) 3.x.x allows remote attackers to read
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Libc - 'regcomp()' Stack Exhaustion Denial of Service
regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
S9Y Serendipity 1.5.5 - 'serendipity[filter][bp.ALT]' Cross-Site Scripting
Serendipity before 1.6 has an XSS issue in the karma plugin which may allow privilege escalation.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android 2.3.5 - PowerVR SGX Driver Information Disclosure
The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jara 1.6 - Multiple Vulnerabilities
Jara 1.6 has an XSS vulnerability
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web File Browser 0.4b14 - File Download
Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to
23RIESGO
abrir ↗Metasploit600
Novell ZENworks Asset Management Remote Execution
Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote at
60RIESGO
abrir ↗Metasploit600
HP Data Protector 6.10/6.11/6.20 Install Service
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that ref
50RIESGO
abrir ↗Exploit-DB
Apache < 2.0.64 / < 2.2.21 mod_setenvif - Integer Overflow
Integer overflow in the ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x th
23RIESGO
abrir ↗Exploit-DB
Apache < 2.0.64 / < 2.2.21 mod_setenvif - Integer Overflow
The ap_pregsub function in server/util.c in the Apache HTTP Server 2.0.x through 2.0.64 and 2.2.x through 2.2.21, when t
23RIESGO
abrir ↗Exploit-DB
CaupoShop Pro (2.x < 3.70) Classic 3.01 - Local File Inclusion
Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BST (BestShopPro) - 'nowosci.php' Multiple Vulnerabilities
SQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB
SetSeed CMS 5.8.20 - 'loggedInUser' SQL Injection
SQL injection vulnerability in setseed-hub in SetSeed CMS 5.8.20, 5.11.2, and earlier allows remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BST (BestShopPro) - 'nowosci.php' Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in nowosci.php in BestShopPro allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.