Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.506Exploit-DB 24.485GitHub PoC 15.787VulnCheck XDB 9186Nuclei 4448Metasploit 3512✓ solo verificadosrecientespopularesriesgo
81.924 exploits
Exploit-DB
DynPG CMS 4.1.0 - 'popup.php' / 'counter.php' Multiple Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is di
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Overflow
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir ↗Exploit-DB
CMS Made Simple 1.7 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple 1.8.1 and earlier allows remote attackers to hijack t
23RIESGO
abrir ↗Exploit-DB
DynPG CMS 4.1.0 - Multiple Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in DynPG CMS 4.1.0, and possibly earlier, when magic_quotes_gpc is di
28RIESGO
abrir ↗Exploit-DB
Joomla! Component Jvehicles - Local File Inclusion
SQL injection vulnerability in the Jvehicles (com_jvehicles) component 1.0, 2.0, and 2.1111 for Joomla! allows remote at
23RIESGO
abrir ↗Exploit-DB
Joomla! Component webERPcustomer - Local File Inclusion
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1
38RIESGO
abrir ↗Exploit-DB
Joomla! Component User Status - Local File Inclusion
Directory traversal vulnerability in userstatus.php in the User Status (com_userstatus) component 1.21.16 for Joomla! al
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TugZip 3.5 Archiver - '.ZIP' File Buffer Overflow
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Centreon IT & Network Monitoring 2.1.5 - SQL Injection
SQL injection vulnerability in main.php in Centreon 2.1.5 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component DW Graph - Local File Inclusion
Directory traversal vulnerability in dwgraphs.php in the DecryptWeb DW Graphs (com_dwgraphs) component 1.0 for Joomla! a
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader - Escape From '.PDF' Execute Embedded Executable
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗Metasploit600
Java Statement.invoke() Trusted Method Chain Privilege Escalation
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18,
100RIESGO
abrir ↗Metasploit600
Java RMIConnectionImpl Deserialization Privilege Escalation
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Piwik 0.5.5 - 'form_url' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Login form in Piwik 0.1.6 through 0.5.5 allows remote attackers to injec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader - Escape From '.PDF' Execute Embedded Executable
Foxit Reader before 3.2.1.0401 allows remote attackers to (1) execute arbitrary local programs via a certain "/Type /Act
23RIESGO
abrir ↗Exploit-DB
OpenDcHub 0.8.1 - Remote Code Execution
Stack-based buffer overflow in Open Direct Connect Hub (aka Open DC Hub or OpenDCHub) 0.8.1 allows remote authenticated
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Stack Buffer Overflow
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir ↗Metasploit300
Novell ZENworks Configuration Management Preboot Service 0x21 Buffer Overflow
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1
23RIESGO
abrir ↗Metasploit600
Novell ZENworks Configuration Management Remote Execution
Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration M
60RIESGO
abrir ↗Metasploit500
Java MixerSequencer Object GM_Song Structure Handling Vulnerability
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pepsi CMS (Irmin cms) pepsi-0.6-BETA2 - Multiple Local File
Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary
23RIESGO
abrir ↗Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'OvWebHelp.exe' CGI Topic Overflow
Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows rem
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy-Clanpage 2.1 - SQL Injection
SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB
Yamamah 1.00 - Multiple Vulnerabilities
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Shadow Stream Recorder 3.0.1.7 - '.asx' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' (PoC)
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pepsi CMS (Irmin cms) pepsi-0.6-BETA2 - Multiple Local File
Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, w
23RIESGO
abrir ↗Exploit-DB
Yamamah 1.00 - Multiple Vulnerabilities
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow (PoC)
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.