Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.415GitHub PoC 15.736VulnCheck XDB 9171Nuclei 4446Metasploit 3509✓ solo verificadosrecientespopularesriesgo
81.759 exploits
Exploit-DB✓ VexDay Proof
TWiki 5.0 - '/bin/view?rev' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inje
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TWiki 5.0 - bin/login Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in lib/TWiki.pm in TWiki before 5.0.1 allow remote attackers to inje
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Jstore - 'Controller' Local File Inclusion
Directory traversal vulnerability in Jstore (com_jstore) component for Joomla! allows remote attackers to read arbitrary
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Winamp 5.5.8.2985 - Multiple Buffer Overflows
Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vect
23RIESGO
abrir ↗Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_PUBLISH.CREATE_CHANGE_SET
Unspecified vulnerability in the Change Data Capture component in Oracle Database Server 10.1.0.5, 10.2.0.4, 11.1.0.7, a
18RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Solaris - 'su' Crash
Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect confidentiality and integrit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Java 6 - OBJECT tag 'launchjnlp'/'docbase' Remote Buffer Overflow
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows r
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.5.10/3.6.6 - 'WMP' Memory Corruption Using Popups
Microsoft Windows Media Player (WMP) 9 through 12 does not properly deallocate objects during a browser reload action, w
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Collabtive 0.65 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Fusion Middleware 10.1.2/10.1.3 - BPEL Console Cross-Site Scripting
Unspecified vulnerability in the BPEL Console component in Oracle Fusion Middleware 11.1.1.1.0 and 11.1.1.2.0 allows rem
23RIESGO
abrir ↗Metasploit400
FileWrangler 5.30 Stack Buffer Overflow
FileWrangler <= 5.30 Stack Buffer Overflow
36RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) 7.53/7.51 - 'OVAS.exe' Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows
60RIESGO
abrir ↗Metasploit400
32bit FTP Client Stack Buffer Overflow
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
43RIESGO
abrir ↗Metasploit400
AASync v2.2.1.0 (Win32) Stack Buffer Overflow (LIST)
AASync.com AASync Stack-based Buffer Overflow
18RIESGO
abrir ↗Metasploit400
FTPShell 5.1 Stack Buffer Overflow
Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP serv
50RIESGO
abrir ↗Metasploit300
Windows Escalate NtUserLoadKeyboardLayoutEx Privilege Escalation
The kernel-mode drivers in Microsoft Windows XP SP3 do not properly perform indexing of a function-pointer table during
43RIESGO
abrir ↗Metasploit400
Gekko Manager FTP Client Stack Buffer Overflow
Gekko Manager FTP Client <= 0.77 Stack Buffer Overflow
36RIESGO
abrir ↗Metasploit400
FTPGetter Standard v3.55.0.05 Stack Buffer Overflow (PWD)
FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-cont
50RIESGO
abrir ↗Metasploit400
FTP Synchronizer Professional 4.0.73.274 Stack Buffer Overflow
FTP Synchronizer Professional <= 4.0.73.274 Stack Buffer Overflow
36RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Collabtive 0.65 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the a
23RIESGO
abrir ↗Metasploit600
Sun Java Web Start BasicServiceImpl Code Execution
Unspecified vulnerability in the Deployment component in Oracle Java SE and Java for Business 6 Update 21 allows remote
60RIESGO
abrir ↗Metasploit600
Oracle VM Server Virtual Server Agent Command Injection
Unspecified vulnerability in the OracleVM component in Oracle VM 2.2.1 allows remote authenticated users to affect confi
50RIESGO
abrir ↗Metasploit400
Seagull FTP v3.3 Build 409 Stack Buffer Overflow
Seagull FTP v3.3 Build 409 Stack Buffer Overflow
36RIESGO
abrir ↗Metasploit500
Sun Java Runtime New Plugin docbase Buffer Overflow
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows r
60RIESGO
abrir ↗Metasploit400
Odin Secure FTP 4.1 Stack Buffer Overflow (LIST)
Odin Secure FTP <= 4.1 Stack Buffer Overflow via LIST Response
36RIESGO
abrir ↗Metasploit400
LeapFTP 3.0.1 Stack Buffer Overflow
LeapFTP < 3.1.x Stack Buffer Overflow
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AdaptCMS 2.0.1 Beta - Remote File Inclusion (Metasploit)
PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is ena
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BaconMap 1.0 - Local File Disclosure
Directory traversal vulnerability in admin/updatelist.php in BaconMap 1.0 allows remote attackers to include and execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BaconMap 1.0 - SQL Injection
SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.