Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.506Exploit-DB 24.485GitHub PoC 15.787VulnCheck XDB 9186Nuclei 4448Metasploit 3512✓ solo verificadosrecientespopularesriesgo
81.924 exploits
Metasploit600
Adobe PDF Embedded EXE Social Engineering
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗Metasploit300
Shadow Stream Recorder 3.0.1.7 Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_weblinks - 'id' SQL Injection
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow (PoC)
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multi Auktions Komplett System 2 - Blind SQL Injection
SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multi Auktions Komplett System 2 - Blind SQL Injection
SQL injection vulnerability in auktion.php in phpscripte24 Niedrig Gebote Pro Auktions System II allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to inject a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Devana - SQL Injection
SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Open Web Analytics 1.2.3 - Multiple File Inclusions
Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Open Web Analytics 1.2.3 - Multiple File Inclusions
PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is dis
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Uebimiau Webmail 2.7.2 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component dcsFlashGames 2.0RC1 - 'catid' SQL Injection
SQL injection vulnerability in Adam Corley dcsFlashGames (com_dcs_flashgames) allows remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari for iPhone/iPod touch - 'Throw' Exception Remote Code Execution
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS Safari - Bad 'VML' Remote Denial of Service
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
UoW IMAPd Server - LSUB Buffer Overflow (Metasploit)
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS Safari - Remote Denial of Service
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP MaxDB - Malformed Handshake Request Remote Code Execution
Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to ex
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari iPhone/iPod touch - Webpage Remote Code Execution
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
justVisual 2.0 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in justVisual CMS 2.0, when magic_quotes_gpc is disabled, allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
INVOhost - SQL Injection
Multiple SQL injection vulnerabilities in INVOhost 3.4 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco TFTP Server 1.1 - Denial of Service
Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RR
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SiteX CMS 0.7.4 Beta - 'photo.php' SQL Injection
SQL injection vulnerability in photo.php in SiteX 0.7.4 beta allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Direct News 4.10.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Direct News 4.10.2, when register_globals is enabled, allow remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lexmark Multiple Laser printers - Remote Stack Overflow
Stack-based buffer overflow in the base, IPDS DLE, Forms DLE, Barcode DLE, Prescribe DLE, and Printcryption DLE componen
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6 - 'gfxTextRun::SanitizeGlyphRuns()' Remote Memory Corruption
The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 be
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Connection Update Manager for Solaris - Multiple Insecure Temporary File Creation Vulnerabilities
Certain patch-installation scripts in Oracle Solaris allow local users to append data to arbitrary files via a symlink a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_jresearch - 'Controller' Local File Inclusion
Directory traversal vulnerability in jresearch.php in the J!Research (com_jresearch) component for Joomla! allows remote
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox/Thunderbird/SeaMonkey - Multiple Memory Corruption Vulnerabilities
The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird befor
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Insky CMS 006-0111 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111, when register_globals is enabled, allow remote
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.