Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.381GitHub PoC 15.712VulnCheck XDB 9162Nuclei 4445Metasploit 3507✓ solo verificadosrecientespopularesriesgo
81.689 exploits
Exploit-DB✓ VexDay Proof
Axis2 / SAP BusinessObjects - (Authenticated) Code Execution (via SOAP) (Metasploit)
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir ↗Metasploit300
Crystal Reports CrystalPrintControl ActiveX ServerResourceVersion Property Overflow
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RIESGO
abrir ↗Metasploit600
MS10-104 Microsoft Office SharePoint Server 2007 Remote Code Execution
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Serve
60RIESGO
abrir ↗Exploit-DB
FontForge - '.BDF' Font File Stack Buffer Overflow (PoC)
Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application cras
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Crystal Reports Viewer 12.0.0.549 - 'PrintControl.dll' ActiveX
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - DHTML Behaviour Use-After-Free (MS10-018) (Metasploit)
Use-after-free vulnerability in the Peer Objects component (aka iepeers.dll) in Microsoft Internet Explorer 6, 6 SP1, an
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Deployer (Authenticated) Code Execution (Metasploit)
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Axis2 - (Authenticated) Code Execution (via REST) (Metasploit)
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Clear iSpot/Clearspot 2.0.0.0 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities on the iSpot 2.0.0.0 R1679, and the ClearSpot 2.0.0.0 R1512 a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Exim 4.63 - Remote Command Execution
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RIESGO
abrir ↗Exploit-DB
PHP 5.3.3 - NumberFormatter::getSymbol Integer Overflow
Integer overflow in the NumberFormatter::getSymbol (aka numfmt_get_symbol) function in PHP 5.3.3 and earlier allows cont
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox/Thunderbird/SeaMonkey - Multiple HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x b
23RIESGO
abrir ↗Exploit-DB
VMware Tools - Update OS Command Injection
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 3
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Archiva 1.0 < 1.3.1 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Redback before 1.2.4, as used in Apache Archiva 1.0 through 1.0.3, 1.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JE Auto 1.0 - SQL Injection
SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - CSS Parser Denial of Service
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RIESGO
abrir ↗Exploit-DB
WonderWare InBatch 9.0sp1 - Buffer Overflow
Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Processing Embed 0.5 - 'pluginurl' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Safe Search - 'v1' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aigaion 1.3.4 - 'ID' SQL Injection
SQL injection vulnerability in indexlight.php in Aigaion 1.3.4 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation
The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs va
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zimplit CMS - 'English_manual_version_2.php?client' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zimplit CMS - 'zimplit.php?File' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation
The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is con
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.