Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.483Referência 24.469GitHub PoC 15.768VulnCheck XDB 9182Nuclei 4447Metasploit 3510✓ solo verificadosrecientespopularesriesgo
81.859 exploits
Exploit-DB
Avast! Internet Security 5.0 - 'aswFW.sys' Kernel Driver IOCTL Memory Pool Corruption
Integer overflow in aswFW.sys 5.0.594.0 in Avast! Internet Security 5.0 Korean Trial allows local users to cause a denia
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FathFTP 1.8 - 'RasIsConnected Method' ActiveX Buffer Overflow (SEH)
Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle MySQL < 5.1.50 - Privilege Escalation
The executable comment feature in MySQL 5.0.x before 5.0.93 and 5.1.x before 5.1.50, when running in certain slave confi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JBoss - Java Class DeploymentFileRepository WAR Deployment (Metasploit)
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS - '.pdf' Local Privilege Escalation 'Jailbreak'
Multiple stack-based buffer overflows in the cff_decoder_parse_charstrings function in the CFF Type2 CharStrings interpr
35RIESGO
abrir ↗Exploit-DB
EMC Celerra NAS Appliance - Unauthorized Access to Root NFS Export
The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle MySQL - 'ALTER DATABASE' Remote Denial of Service
MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (serve
23RIESGO
abrir ↗Metasploit300
Amlibweb NetOpacs webquery.dll Stack Buffer Overflow
Amlibweb NetOpacs webquery.dll Stack Buffer Overflow
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS - '.pdf' Local Privilege Escalation 'Jailbreak'
Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allo
23RIESGO
abrir ↗Exploit-DB
Joomla! Component CamelcityDB 2.2 - SQL Injection
SQL injection vulnerability in the CamelcityDB (com_camelcitydb2) component 2.2 for Joomla! allows remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Barcodewiz Barcode ActiveX Control 3.29 - Remote HeapSpray (Internet Explorer 6/7)
Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SigPlus Pro 3.74 - ActiveX 'LCDWriteString()' Remote Buffer Overflow JIT Spray (ASLR + DEP Bypass)
Stack-based buffer overflow in SigPlus Pro 3.74 ActiveX control allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Barcodewiz Barcode ActiveX Control 3.29 - Remote Buffer Overflow (SEH)
Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Barcodewiz BarCode ActiveX 3.29 - Denial of Service (PoC)
Buffer overflow in BarCodeWiz BarCode 3.29 ActiveX control (BarcodeWiz.dll) allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Metasploit300
WM Downloader 3.1.2.2 Buffer Overflow
WM Downloader 3.1.2.2 Buffer Overflow via Malformed M3U File
36RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RIESGO
abrir ↗Exploit-DB
AV Arcade 3 - Cookie Authentication Bypass
SQL injection vulnerability in AV Scripts AV Arcade 3 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KVIrc 4.0 - '\r' Carriage Return in DCC Handshake Remote Command Execution
The IRC Protocol component in KVIrc 3.x and 4.x before r4693 does not properly handle \ (backslash) characters, which al
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Impact Software AdPeeps - Cross-Site Scripting / HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdPeeps 8.5d1 allow remote attackers to inject arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hyleos ChemView - ActiveX Control Stack Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos Ch
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
nuBuilder 10.04.20 - Local File Inclusion
Directory traversal vulnerability in productionnu2/fileuploader.php in nuBuilder 10.04.20, and possibly other versions b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component TTVideo 1.0 - SQL Injection
SQL injection vulnerability in ttvideo.php in the TTVideo (com_ttvideo) component 1.0 for Joomla! allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Visites 1.1 RC2 - Remote File Inclusion
PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites (com_joomla-visites) component
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Freeway CMS 1.4.3.210 - SQL Injection
SQL injection vulnerability in index.php in Freeway CMS 1.4.3.210 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
httpdx - 'h_handlepeer()' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote at
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
sSMTP 2.62 - 'standardize()' Buffer Overflow
The standardise function in Anibal Monsalve Salazar sSMTP 2.61 and 2.62 allows local users to cause a denial of service
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component FreiChat 1.0/2.x - HTML Injection
Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure
23RIESGO
abrir ↗Metasploit600
Symantec System Center Alert Management System (hndlrsvc.exe) Arbitrary Command Execution
HDNLRSVC.EXE in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (a
30RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Simple PHP Blog 0.4.0 - Remote Command Execution (Metasploit)
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which cou
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.