Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.483Referência 24.469GitHub PoC 15.768VulnCheck XDB 9182Nuclei 4447Metasploit 3510✓ solo verificadosrecientespopularesriesgo
81.859 exploits
Exploit-DB
Microsoft Windows - 'SfnLOGONNOTIFY' Privilege Escalation (MS10-048)
The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nasim Guest Book - 'page' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Nasim Guest Book 1.2 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB
PHP-Nuke 8.x - Blind SQL Injection
SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.33.3 - SCTP INIT Remote Denial of Service
The sctp_process_unk_param function in net/sctp/sm_make_chunk.c in the Linux kernel 2.6.33.3 and earlier, when SCTP is e
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fat Player 0.6b - '.WAV' File Processing Buffer Overflow (SEH)
Stack-based buffer overflow in Fat Player 0.6b allows remote attackers to execute arbitrary code via a long string in a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Allinta CMS 22.07.2010 - Multiple SQL Injections / Cross-Site Scripting Vulnerabilities
Multiple SQL injection vulnerabilities in Allinta CMS 22.07.2010 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPKick 0.8 - 'Statistics.php' SQL Injection
SQL injection vulnerability in statistics.php in PHPKick 0.8 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tycoon CMS Record Script 1.0.9 - SQL Injection
SQL injection vulnerability in index.php in Tycoon Baseball Script 1.0.9 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RealServer - Describe Buffer Overflow (Metasploit)
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbit
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java Web Server - System WebDAV OPTIONS Buffer Overflow (Metasploit)
Stack-based buffer overflow in the WebDAV implementation in webservd in Sun Java System Web Server (aka SJWS) 7.0 Update
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LibTIFF - 'td_stripbytecount' Null Pointer Dereference Remote Denial of Service
LibTIFF 3.9.4 and earlier does not properly handle an invalid td_stripbytecount field, which allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSL - 'ssl3_get_key_exchange()' Use-After-Free Memory Corruption
Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Subversion - Date Svnserve (Metasploit)
Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attacker
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EFS Easy Chat Server - Authentication Request Handling Buffer Overflow (Metasploit)
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'win32k.sys' Driver 'CreateDIBPalette()' Local Buffer Overflow
Buffer overflow in the CreateDIBPalette function in win32k.sys in Microsoft Windows XP SP3, Server 2003 R2 Enterprise SP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
APBoard 2.1.0 - 'board.php?id' SQL Injection
SQL injection vulnerability in board/board.php in APBoard Developers APBoard 2.1.0 and earlier allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nuked-klaN Module Partenaires NK 1.5 - Blind SQL Injection
SQL injection vulnerability in clic.php in the Partenaires module 1.5 for Nuked-Klan allows remote attackers to execute
23RIESGO
abrir ↗Exploit-DB
Open Blog 1.2.1 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Tomaz Muraus Open Blog 1.2.1, and possibly earlier, allows remote att
23RIESGO
abrir ↗Exploit-DB
Open Blog 1.2.1 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in application/modules/admin/controllers/users.php in Tomaz Muraus Open
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DiamondList 0.1.6 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in user/main/update_user in DiamondList 0.1.6, and possibly e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
uzbl 'uzbl-core' - '@SELECTED_URI' Mouse Button Bindings Command Injection
The default configuration of the <Button2> binding in Uzbl before 2010.08.05 does not properly use the @SELECTED_URI fea
23RIESGO
abrir ↗Metasploit300
JBoss Seam 2 File Upload and Execute
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DiamondList - '/user/main/update_category?category[description]' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in DiamondList 0.1.6, and possibly earlier, allow remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hulihan Applications BXR 0.6.8 - SQL Injection / HTML Injection
SQL injection vulnerability in folder/list in Hulihan BXR 0.6.8 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ccTiddly 1.7.6 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in ccTiddly 1.7.4 and 1.7.6 allow remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DiamondList - '/user/main/update_settings?setting[site_title]' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in DiamondList 0.1.6, and possibly earlier, allow remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy RM to MP3 2.7.3.700 - '.m3u' / '.pls' / '.smi' / '.wpl' / '.wax' / '.wvx' / '.ram' Local Overflow
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long fil
28RIESGO
abrir ↗Metasploit300
Novell iPrint Client ActiveX Control ExecuteRequest debug Buffer Overflow
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RIESGO
abrir ↗Metasploit500
HP NNM CGI webappmon.exe OvJavaLocale Buffer Overflow
Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote at
50RIESGO
abrir ↗Exploit-DB
EMC Celerra NAS Appliance - Unauthorized Access to Root NFS Export
The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.