Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
81.689 exploits
Exploit-DB
HP JetDirect PJL - Query Execution (Metasploit)
The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printer
28RIESGO
abrir ↗Metasploit300
BisonWare BisonFTP Server Buffer Overflow
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly
50RIESGO
abrir ↗Exploit-DB
HP JetDirect PJL - Interface Universal Directory Traversal (Metasploit)
The default configuration of the PJL Access value in the File System External Access settings on HP LaserJet MFP printer
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Social Slider 5.6.5 - SQL Injection
SQL injection vulnerability in social-slider-2/ajax.php in the Social Slider plugin before 7.4.2 for WordPress allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6.16 - OBJECT mChannel Remote Code Execution (DEP Bypass) (Metasploit)
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allo
60RIESGO
abrir ↗Exploit-DB
OpenSLP 1.2.1 / < 1647 trunk - Denial of Service
The extension parser in slp_v2message.c in OpenSLP 1.2.1, and other versions before SVN revision 1647, as used in Servic
28RIESGO
abrir ↗Exploit-DB
HP Data Protector (HP-UX) - Remote Shell
The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun/Oracle GlassFish Server - (Authenticated) Code Execution (Metasploit)
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Applicati
50RIESGO
abrir ↗Metasploit600
Sun/Oracle GlassFish Server Authenticated Code Execution
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Applicati
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zinf Audio Player 2.2.1 - '.pls' Local Buffer Overflow (DEP Bypass)
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin TimThumb 1.32 - Remote Code Execution
TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kolibri HTTP Server 2.0 - HEAD Buffer Overflow (Metasploit)
Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Open Handset Alliance Android 2.3.4/3.1 - Browser Sandbox Security Bypass
Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local
23RIESGO
abrir ↗Exploit-DB
ZoneMinder 1.24.3 - Remote File Inclusion
Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chyrp 2.x - '/includes/lib/gz.php?File' Traversal Arbitrary File Access
Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitr
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chyrp 2.x - 'action' Traversal Local File Inclusion
Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary loca
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chyrp 2.x swfupload Extension - 'upload_handler.php' Arbitrary File Upload / Arbitrary PHP Code Execution
upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Network Automation 9.10 - SQL Injection
SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SWAT Samba Web Administration Tool - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x befo
28RIESGO
abrir ↗Exploit-DB
Apple Safari 5.0.5 - SVG Remote Code Execution (DEP Bypass)
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of ser
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'tasks.php?selected[]' SQL Injection
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'report_marketing.php?exc[]' SQL Injection
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'search.php?search_string' SQL Injection
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'billable_incidents.php?sites[]' SQL Injection
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA Arcserve D2D - GWT RPC Credential Information Disclosure (Metasploit)
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain
60RIESGO
abrir ↗Exploit-DB
Apple Safari 5.0.6/5.1 - SVG DOM Processing (PoC)
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of ser
28RIESGO
abrir ↗Metasploit600
CA Arcserve D2D GWT RPC Credential Information Disclosure
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain
60RIESGO
abrir ↗Exploit-DB
Oracle Sun GlassFish Enterprise Server - Persistent Cross-Site Scripting
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote atta
23RIESGO
abrir ↗Metasploit600
Apple Safari Webkit libxslt Arbitrary File Creation
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tiki Wiki CMS Groupware 7.2 - 'snarf_ajax.php' Cross-Site Scripting
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.