Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
81.689 exploits
Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.37-rc2 - 'ACPI custom_method' Local Privilege Escalation
The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mafia Game Script - SQL Injection
SQL injection vulnerability in profil.php in Mafya Oyun Scrpti (aka Mafia Game Script) allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Projekt Shop - 'details.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in MH Products Projekt Shop allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.37-rc2 - 'ACPI custom_method' Local Privilege Escalation
drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local users to modify arbitrary kernel memory locations by
23RIESGO
abrir ↗Exploit-DB
Radius Manager 3.8.0 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Radius Manager 3.6 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Radius Manager 3.8.0 allow remote authenticated administrators to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k Pointer Dereferencement (PoC) (MS10-098)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 and Windows 7 does not properly validate user-
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Immo Makler Script - SQL Injection
SQL injection vulnerability in news.php in Immo Makler allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MHP Downloadshop - SQL Injection
SQL injection vulnerability in view_item.php in MH Products MHP Downloadshop allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy Online Shop - SQL Injection
SQL injection vulnerability in content.php in MH Products Easy Online Shop allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Exim4 < 4.69 - string_format Function Heap Buffer Overflow (Metasploit)
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specif
91RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Altap Salamander 2.5 PE Viewer - Local Buffer Overflow (Metasploit)
Stack-based buffer overflow in peviewer.spl in Altap Servant Salamander 2.5 with Portable Executable Viewer 2.02 (Englis
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe PDF - Embedded EXE Social Engineering (Metasploit)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JRadio - Local File Inclusion
Directory traversal vulnerability in JRadio (com_jradio) component before 1.5.1 for Joomla! allows remote attackers to r
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe PDF - Escape EXE Social Engineering (No JavaScript) (Metasploit)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Exim4 < 4.69 - string_format Function Heap Buffer Overflow (Metasploit)
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RIESGO
abrir ↗Exploit-DB
Blog:CMS 4.2.1e - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to
23RIESGO
abrir ↗Exploit-DB
Pointter PHP Micro-Blogging Social Network - Unauthorized Privilege Escalation
Pointter PHP Micro-Blogging Social Network 1.8 allows remote attackers to bypass authentication and obtain administrativ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Tivoli Storage Manager (TSM) - Local Privilege Escalation
Stack-based buffer overflow in the GeneratePassword function in dsmtca (aka the Trusted Communications Agent or TCA) in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Java - 'Statement.invoke()' Trusted Method Chain (Metasploit)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18,
100RIESGO
abrir ↗Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
Cross-site scripting (XSS) vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attacker
23RIESGO
abrir ↗Exploit-DB
Pointter PHP Content Management System - Unauthorized Privilege Escalation
Pointter PHP Content Management System 1.0 allows remote attackers to bypass authentication and obtain administrative pr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attack
23RIESGO
abrir ↗Exploit-DB
BEdita 3.0.1.2550 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the aut
23RIESGO
abrir ↗Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Cross-Site Scripting / Full Path Disclosure
admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an inv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - CSS Parser
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RIESGO
abrir ↗Exploit-DB
Blog:CMS 4.2.1e - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in admin/libs/ADMIN.php in BLOG:CMS 4.2.1.e, and possibly earlier, allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
gitWeb 1.7.3.3 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Gitweb 1.7.3.3 and earlier allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB
Mantis Bug Tracker 1.2.3 - 'db_type' Local File Inclusion
Directory traversal vulnerability in admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to in
23RIESGO
abrir ↗Metasploit500
MS11-006 Microsoft Windows CreateSizedDIBSECTION Stack Buffer Overflow
Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.