Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.415GitHub PoC 15.736VulnCheck XDB 9171Nuclei 4446Metasploit 3509✓ solo verificadosrecientespopularesriesgo
81.759 exploits
Metasploit500
MOXA Device Manager Tool 2.1 Buffer Overflow
Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MD
43RIESGO
abrir ↗Exploit-DB
Oracle JRE - java.net.URLConnection class Same-of-Origin 'SOP' Policy Bypass
Unspecified vulnerability in the Networking component in Oracle Java SE and Java for Business 6 Update 21 and 5.0 Update
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
4Site CMS 2.6 - 'cat' SQL Injection
SQL injection vulnerability in catalog/index.shtml in 4site CMS 2.6, and possibly earlier, allows remote attackers to ex
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox SeaMonkey 3.6.10 / Thunderbird 3.1.4 - 'document.write' Memory Corruption
Stack-based buffer overflow in the text-rendering functionality in Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11
28RIESGO
abrir ↗Metasploit200
MOXA MediaDBPlayback ActiveX Control Buffer Overflow
Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows r
50RIESGO
abrir ↗Exploit-DB
phpCheckZ 1.1.0 - Blind SQL Injection
SQL injection vulnerability in chart.php in phpCheckZ 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Winamp 5.5.8 (in_mod plugin) - Local Stack Overflow
Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vect
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.36-rc8 - 'RDS Protocol' Local Privilege Escalation
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JBoss JMX - Console Deployer Upload and Execute (Metasploit)
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU C library dynamic linker - '$ORIGIN' Expansion
Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU C library dynamic linker - '$ORIGIN' Expansion
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Piranha Virtual Server Package - 'passwd.php3' Arbitrary Command Execution (Metasploit)
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password tha
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Brooky CubeCart 2.0.1 - SQL Injection
SQL injection vulnerability in index.php in CubeCart 2.0.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Metasploit600
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RIESGO
abrir ↗Metasploit600
glibc LD_AUDIT Arbitrary DSO Load Privilege Escalation
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fat Player 0.6b - '.wav' Local Buffer Overflow (SEH)
Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a
50RIESGO
abrir ↗Metasploit300
Fat Player Media Player 0.6b0 Buffer Overflow
Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a
50RIESGO
abrir ↗Metasploit600
glibc '$ORIGIN' Expansion Privilege Escalation
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Piranha Virtual Server Package - 'passwd.php3' Arbitrary Command Execution (Metasploit)
The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary command
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NTLM Weak Nonce (MS10-012)
The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kisisel Radyo Script - Multiple Vulnerabilities
Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kisisel Radyo Script - Multiple Vulnerabilities
SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft ASP.NET - Padding Oracle File Download (MS10-070)
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Intern
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office - 'HtmlDlgHelper' Class Memory Corruption (MS10-071)
mshtmled.dll in Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code via a crafted Micr
28RIESGO
abrir ↗Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon recei
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DATAC RealWin SCADA Server 2.0 (Build 6.1.8.10) - Buffer Overflow
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RIESGO
abrir ↗Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
solid.exe in IBM solidDB 6.5.0.3 and earlier does not properly perform a recursive call to a certain function upon recei
23RIESGO
abrir ↗Metasploit500
DATAC RealWin SCADA Server SCPC_INITIALIZE_RF Buffer Overflow
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RIESGO
abrir ↗Metasploit500
DATAC RealWin SCADA Server SCPC_INITIALIZE Buffer Overflow
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RIESGO
abrir ↗Exploit-DB
IBM solidDB 6.5.0.3 - Denial of Service
Stack consumption vulnerability in solid.exe in IBM solidDB 6.5.0.3 and earlier allows remote attackers to cause a denia
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.