Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
81.689 exploits
Metasploit600
Wireshark console.lua Pre-Loading Script Execution
Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain pr
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GDI+ - 'gdiplus.dll' CreateDashedPath Integer Overflow
Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'Toolbar.exe' CGI Cookie Handling Buffer Overflow (Metasploit)
Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Java RMI - Server Insecure Default Configuration Java Code Execution (Metasploit)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RIESGO
abrir ↗Metasploit300
Citrix Gateway ActiveX Control Stack Based Buffer Overflow Vulnerability
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Ed
50RIESGO
abrir ↗Metasploit600
LifeSize Room Command Injection
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitra
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chyrp 2.x - '/admin/help.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chyrp 2.x - '/includes/JavaScript.php?action' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Flowplayer 3.2.7 - 'linkUrl' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) ext
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'nsTreeRange' Dangling Pointer (Metasploit) (1)
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange da
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 3.x - Swekey Remote Code Injection
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restric
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Backup Exec 12.5 - Man In The Middle
Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 3.x - Swekey Remote Code Injection
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Blue Coat Authentication and Authorization Agent (BCAAA) 5 - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 an
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin3 (pma3) - Remote Code Execution
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin3 (pma3) - Remote Code Execution
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restric
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MicroP 0.1.1.1600 - '.mppl' Local Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RIESGO
abrir ↗Exploit-DB
ManageEngine ServiceDesk 8.0.0.12 - Database Disclosure
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remo
35RIESGO
abrir ↗Exploit-DB
ManageEngine ServiceDesk 8.0.0.12 - Database Disclosure
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RIESGO
abrir ↗Metasploit600
WeBid converter.php Remote PHP Code Injection
WeBid 1.0.2 converter.php Remote PHP Code Injection
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution (Metasploit)
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader 5.1 - XFDF Buffer Overflow (SEH)
Stack-based buffer overflow in the OutputDebugString function for Adobe Acrobat Reader 5.1 allows remote attackers to ex
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.3.6 - Local Buffer Overflow (ROP)
Stack-based buffer overflow in the socket_connect function in ext/sockets/sockets.c in PHP 5.3.3 through 5.3.6 might all
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP OmniInet.exe Opcode 20 - Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader X 10.0.0 < 10.0.1 - Atom Type Confusion
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RIESGO
abrir ↗Metasploit600
VSFTPD 2.3.4 Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗Exploit-DB
Microsoft IIS 7.0 FTP Server - Stack Exhaustion Denial of Service (MS09-053) (Metasploit)
Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allo
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2010 - '.RTF' Header Stack Overflow
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector 6.11 - Remote Buffer Overflow (DEP Bypass)
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir ↗Metasploit300
Kaillera 0.86 Server Denial of Service
Kaillera 0.86 Server DoS via Malformed UDP Packet
36RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.