Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9136Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
81.524 exploits
Exploit-DB✓ VexDay Proof
Microsoft Win32k - Null Pointer De-reference (PoC) (MS11-077)
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpLDAPadmin 1.2.1.1 - Remote PHP Code Injection (1)
Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB
SportsPHool 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DELL Quest One Password Manager - CAPTCHA Security Bypass
The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sens
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Power Manager - 'formExportDataLogs' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to ex
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pre Studio Business Cards Designer - SQL Injection
SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB
OCS Inventory NG 2.0.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers t
23RIESGO
abrir ↗Metasploit300
HP Power Manager 'formExportDataLogs' Buffer Overflow
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to ex
60RIESGO
abrir ↗Metasploit300
AdminStudio LaunchHelp.dll ActiveX Arbitrary Code Execution
Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in Laun
50RIESGO
abrir ↗Metasploit600
Java Applet Rhino Script Engine Remote Code Execution
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari Webkit - libxslt Arbitrary File Creation (Metasploit)
xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari Webkit - libxslt Arbitrary File Creation (Metasploit)
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Toshiba e-Studio (Multiple Devices) - Security Bypass
The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmwa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari - 'file://' Arbitrary Code Execution (Metasploit)
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers
50RIESGO
abrir ↗Exploit-DB
GNUBoard 4.33.02 - 'tp.php?PATH_INFO' SQL Injection
SQL injection vulnerability in bbs/tb.php in Gnuboard 4.33.02 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Metasploit300
Java RMI Server Insecure Endpoint Code Execution Scanner
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RIESGO
abrir ↗Metasploit600
Java RMI Server Insecure Default Configuration Java Code Execution
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RIESGO
abrir ↗Exploit-DB
Microsoft Windows - TCP/IP Stack Denial of Service (MS11-064)
Tcpip.sys in the TCP/IP stack in Microsoft Windows 7 Gold and SP1 and Windows Server 2008 R2 and R2 SP1 does not properl
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vTiger CRM 5.2 - 'onlyforuser' SQL Injection
SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsys PROMOTIC 8.1.4 - ActiveX GetPromoticSite Unitialized Pointer
Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsys PROMOTIC 8.1.4 - ActiveX GetPromoticSite Unitialized Pointer
Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - '.fon' Kernel-Mode Buffer Overrun (PoC) (MS11-077)
Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, W
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsys PROMOTIC 8.1.4 - ActiveX GetPromoticSite Unitialized Pointer
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'Array.reduceRight()' Integer Overflow (Metasploit) (2)
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'Array.reduceRight()' Integer Overflow (1)
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PcVue 10.0 SV.UIGrdCtrl.1 - 'LoadObject()'/'SaveObject()' Trusted DWORD (Metasploit)
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows
43RIESGO
abrir ↗Metasploit400
ScriptFTP LIST Remote Buffer Overflow
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long file
50RIESGO
abrir ↗Metasploit300
Apple Safari file:// Arbitrary Code Execution
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SilverStripe CMS 2.4.5 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TugZip 3.5 Archiver - '.ZIP' File Parsing Buffer Overflow (Metasploit)
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.