Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.081 exploits
Exploit-DB✓ VexDay Proof
Free Download Manager - '.Torrent' File Parsing Multiple Buffer Overflow Vulnerabilities (Metasploit)
Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Bui
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews and UTF-8 CuteNews - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews and UTF-8 CuteNews - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews 1.4.6 - 'search.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6, when register_globals is enabled and magi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews and UTF-8 CuteNews - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews 1.4.6 editnews Module - doeditnews Action Admin Moderation Bypass
The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews 1.4.6 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews 8 and 8b, when magic_
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.8.0 - Denial of Service (Metasploit)
Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote attackers to cause a denial of service via a long argument to th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews 1.4.6 - 'result' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allow remote
23RIESGO
abrir ↗Metasploit300
Microsoft Windows EOT Font Table Directory Integer Overflow
win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse fon
50RIESGO
abrir ↗Metasploit400
MS09-067 Microsoft Excel Malformed FEATHEADER Record Vulnerability
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Conv
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla NSS - NULL Character CA SSL Certificate Validation Security Bypass
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.31.4 - 'unix_stream_connect()' Local Denial of Service
net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews and UTF-8 CuteNews - Multiple Vulnerabilities
CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an inval
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews 1.4.6 - 'from_date_day' Full Path Disclosure
CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to obtain sensitive information via an inval
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews 1.4.6 - 'index.php' Cross-Site Request Forgery (New User Creation)
Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews and UTF-8 CuteNews - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP-Cumulus 1.x - 'tagcloud.swf' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for Wor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'fput()' Null Pointer Dereference Local Denial of Service
The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management uni
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache mod_perl - 'Apache::Status' / 'Apache2::Status' Cross-Site Scripting
20RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache mod_perl - 'Apache::Status' / 'Apache2::Status' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Status.pm in Apache::Status and Apache2::Status in mod_perl1 and mod_perl2 f
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader / Acrobat - '.U3D' File Invalid Array Index Overflow
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might all
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - Ext4 'move extents' ioctl Privilege Escalation
The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-g
23RIESGO
abrir ↗Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RIESGO
abrir ↗Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RIESGO
abrir ↗Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RIESGO
abrir ↗Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RIESGO
abrir ↗Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RIESGO
abrir ↗Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RIESGO
abrir ↗Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.