Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.541Exploit-DB 24.485GitHub PoC 15.811VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.004 exploits
Exploit-DB
HP OpenView Network Node Manager (OV NNM) - 'OvWebHelp.exe' CGI Topic Overflow
Heap-based buffer overflow in OvWebHelp.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows rem
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB
Yamamah 1.00 - Multiple Vulnerabilities
SQL injection vulnerability in index.php in Yamamah Photo Gallery 1.00, as distributed before 20100618, allows remote at
23RIESGO
abrir ↗Metasploit500
Java MixerSequencer Object GM_Song Structure Handling Vulnerability
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 18, 5.0 Update 23, 1.4
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Shadow Stream Recorder 3.0.1.7 - '.asx' Local Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pepsi CMS (Irmin cms) pepsi-0.6-BETA2 - Multiple Local File
Directory traversal vulnerability in Irmin CMS (formerly Pepsi CMS) 0.6 BETA2 allows remote attackers to read arbitrary
23RIESGO
abrir ↗Exploit-DB
Yamamah 1.00 - Multiple Vulnerabilities
SQL injection vulnerability in index.php in Yamamah (aka Dove Photo Album) 1.00 allows remote attackers to execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' (PoC)
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pepsi CMS (Irmin cms) pepsi-0.6-BETA2 - Multiple Local File
Directory traversal vulnerability in includes/template-loader.php in Irmin CMS (formerly Pepsi CMS) 0.5 and 0.6 BETA2, w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy-Clanpage 2.1 - SQL Injection
SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute a
23RIESGO
abrir ↗Metasploit600
Novell ZENworks Configuration Management Remote Execution
Directory traversal vulnerability in UploadServlet in the Remote Management component in Novell ZENworks Configuration M
60RIESGO
abrir ↗Metasploit300
Novell ZENworks Configuration Management Preboot Service 0x21 Buffer Overflow
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1
23RIESGO
abrir ↗Metasploit300
Shadow Stream Recorder 3.0.1.7 Buffer Overflow
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_weblinks - 'id' SQL Injection
SQL injection vulnerability in the Weblinks (com_weblinks) component in Joomla! allows remote attackers to execute arbit
23RIESGO
abrir ↗Metasploit600
Adobe PDF Embedded EXE Social Engineering
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗Metasploit600
Adobe PDF Escape EXE Social Engineering (No JavaScript)
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASX to MP3 Converter 3.0.0.100 - Local Stack Overflow (PoC)
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to inject a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Devana - SQL Injection
SQL injection vulnerability in profile_view.php in Devana 1.6.6 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multi Auktions Komplett System 2 - Blind SQL Injection
SQL injection vulnerability in auktion.php in Multi Auktions Komplett System 2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TSOKA:CMS 1.1/1.9/2.0 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multi Auktions Komplett System 2 - Blind SQL Injection
SQL injection vulnerability in auktion.php in phpscripte24 Niedrig Gebote Pro Auktions System II allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Uebimiau Webmail 2.7.2 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in Uebimiau 2.7.2 through 2.7.10 allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Open Web Analytics 1.2.3 - Multiple File Inclusions
PHP remote file inclusion vulnerability in mw_plugin.php in Open Web Analytics (OWA) 1.2.3, when magic_quotes_gpc is dis
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Open Web Analytics 1.2.3 - Multiple File Inclusions
Multiple directory traversal vulnerabilities in index.php in Open Web Analytics (OWA) 1.2.3 might allow remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP MaxDB - Malformed Handshake Request Remote Code Execution
Stack-based buffer overflow in serv.exe in SAP MaxDB 7.4.3.32, and 7.6.0.37 through 7.6.06 allows remote attackers to ex
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS Safari - Bad 'VML' Remote Denial of Service
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
UoW IMAPd Server - LSUB Buffer Overflow (Metasploit)
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS Safari - Remote Denial of Service
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari for iPhone/iPod touch - 'Throw' Exception Remote Code Execution
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.