Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
81.689 exploits
Metasploit600
Plone and Zope XMLTools Remote Command Execution
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vTiger CRM 5.2.1 - 'PHPrint.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome < 14.0.835.163 - '.pdf' File Handling Memory Corruption
Google Chrome before 14.0.835.163 does not properly perform garbage collection during the processing of PDF documents, w
23RIESGO
abrir ↗Exploit-DB
CF Image Hosting Script 1.3.82 - File Disclosure
Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vTiger CRM 5.2.1 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities (1)
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arb
23RIESGO
abrir ↗Exploit-DB
JBoss & JMX Console - Misconfigured Deployment Scanner
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Phorum 5.2.18 - '/admin/index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin.php in Phorum 5.2.18 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netvolution 2.5.8 - 'referer' Header SQL Injection
SQL injection vulnerability in ATCOM Netvolution 2.5.8 ASP allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ContaoCMS 2.10.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Perl 5.x - Digest Module 'Digest->new()' Code Injection
Eval injection vulnerability in the Digest module before 1.17 for Perl allows context-dependent attackers to execute arb
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SonicWALL Viewpoint 6.0 - 'scheduleID' SQL Injection
SQL injection vulnerability in sgms/reports/scheduledreports/configure/scheduleProps.jsp in SonicWall ViewPoint 6.0 SP2
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Banana Dance CMS and Wiki - SQL Injection
SQL injection vulnerability in user.php in Banana Dance before B.1.5 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Exploit-DB
Adobe Photoshop Elements 8.0 - Multiple Arbitrary Code Execution Vulnerabilities
Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of servic
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA Total Defense Suite - reGenerateReports Stored procedure SQL Injection (Metasploit)
Multiple SQL injection vulnerabilities in the Unified Network Control (UNC) Server in CA Total Defense (TD) r12 before S
60RIESGO
abrir ↗Metasploit400
Cytel Studio 9.0 (CY3 File) Stack Buffer Overflow
Cytel Studio <= 9.0 .CY3 File Stack Buffer Overflow
43RIESGO
abrir ↗Metasploit600
Apache Struts ParametersInterceptor Remote Code Execution
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Polipo 1.0.4.1 - POST/PUT HTTP Header Processing Denial of Service
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - UIPC socket heap Overflow (PoC)
Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Theme Morning Coffee 3.5 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Morning Coffee theme before 3.6 for WordPress allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Theme Black-LetterHead 1.5 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Black-LetterHead theme before 1.6 for WordPress allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Theme RedLine 1.65 - 's' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the RedLine theme before 1.66 for WordPress allows remote attackers to injec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Theme Atahualpa 3.6.7 - 's' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Atahualpa theme before 3.6.8 for WordPress allows remote attackers to in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Theme EvoLve 1.2.5 - 's' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the EvoLve theme before 1.2.6 for WordPress allows remote attackers to injec
23RIESGO
abrir ↗Exploit-DB
ScriptFTP 3.3 - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long file
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Theme Pixiv Custom Theme 2.1.5 - 'cpage' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Pixiv Custom theme before 2.1.6 for WordPress allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Theme Elegant Grunge 1.0.3 - 's' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Elegant Grunge theme before 1.0.4 for WordPress allows remote attackers
23RIESGO
abrir ↗Exploit-DB
Apple Mac OSX < 10.6.7 - Kernel Panic (Denial of Service)
The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which al
23RIESGO
abrir ↗Exploit-DB
Omnidocs - Multiple Vulnerabilities
Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PcVue 10.0 - Multiple Vulnerabilities
Buffer overflow in an unspecified ActiveX control in aipgctl.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.