Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
81.689 exploits
Metasploit300
Apple Safari file:// Arbitrary Code Execution
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers
50RIESGO
abrir ↗Metasploit400
ScriptFTP LIST Remote Buffer Overflow
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long file
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - Select Element Memory Corruption
Microsoft Internet Explorer 8 does not properly allocate and access memory, which allows remote attackers to execute arb
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TugZip 3.5 Archiver - '.ZIP' File Parsing Buffer Overflow (Metasploit)
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache mod_proxy - Reverse Proxy Exposure
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SilverStripe CMS 2.4.5 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in the process function in SSViewer.php in SilverStripe before 2.3.13 and 2.4.x
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.18 - 'adduser.asp' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ACDSee FotoSlate - '.PLP' File 'id' Local Overflow (Metasploit)
Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
Directory traversal vulnerability in the web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly validate values in HTTP requests, w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 does not properly check return values from functions,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.18 - 'addgroup.asp?group' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyBB Forum Userbar Plugin (Userbar 2.2) - SQL Injection
SQL injection vulnerability in userbarsettings.php in the Userbar plugin 2.2 for MyBB Forum allows remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
atvise webMI2ADS Web Server 1.0 - Multiple Vulnerabilities
The web server in Certec atvise webMI2ADS (aka webMI) before 2.0.2 allows remote attackers to cause a denial of service
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.18 - 'addlimit.asp?url' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GoAhead Webserver 2.18 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OPC Systems.NET 4.00.0048 - Denial of Service
Open Automation Software OPC Systems.NET before 5.0 allows remote attackers to cause a denial of service via a malformed
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyBB Advanced Forum Signatures - 'afsignatures-2.0.4' SQL Injection
Multiple SQL injection vulnerabilities in signature.php in the Advanced Forum Signatures (aka afsignatures) plugin 2.0.4
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyBB Advanced Forum Signatures - 'afsignatures-2.0.4' SQL Injection
SQL injection vulnerability in signature.php in Advanced Forum Signatures plugin (aka afsignatures) 2.0.4 for MyBB allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptFTP 3.3 - LIST Remote Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long file
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Time Returns 2.0 - SQL Injection
SQL injection vulnerability in the Time Returns (com_timereturns) component 2.0 and possibly earlier versions for Joomla
23RIESGO
abrir ↗Exploit-DB
NexusPHP 1.5 - SQL Injection
SQL injection vulnerability in thanks.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB
pkexec - Race Condition Privilege Escalation
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privil
38RIESGO
abrir ↗Exploit-DB
BlazeVideo HDTV Player 6.6 Professional - Universal ASLR + DEP Bypass
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.3.11/5.4.0RC2 - 'header()' HTTP Header Injection
The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequenc
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Active CMS 1.2 - 'mod' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the admin script in Active CMS 1.2 allows remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 10/11 - Bad Nesting with Frameset Tag Memory Corruption (Metasploit)
Opera before 11.11 does not properly implement FRAMESET elements, which allows remote attackers to execute arbitrary cod
28RIESGO
abrir ↗Metasploit600
myBB 1.6.4 Backdoor Arbitrary Command Execution
myBB 1.6.4 Backdoor Arbitrary Command Execution
63RIESGO
abrir ↗Metasploit200
PcVue 10.0 SV.UIGrdCtrl.1 'LoadObject()/SaveObject()' Trusted DWORD Vulnerability
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows
43RIESGO
abrir ↗Metasploit600
Spreecommerce 0.60.1 Arbitrary Command Execution
Spreecommerce < 0.60.2 Search Parameter RCE
63RIESGO
abrir ↗Exploit-DB
PolicyKit polkit-1 < 0.101 - Local Privilege Escalation
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privil
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.