Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.566Exploit-DB 24.485GitHub PoC 15.863VulnCheck XDB 9205Nuclei 4449Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.081 exploits
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.26 - Auerswald USB Device Driver Buffer Overflow (PoC)
Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 all
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TBmnetCMS 1.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in TBmnetCMS 1.0 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mambo Component com_koesubmit 1.0.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in koesubmit.php in the koeSubmit (com_koesubmit) component 1.0 for Mambo allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun VirtualBox 3.0.6 - Local Privilege Escalation
Unspecified vulnerability in the VBoxNetAdpCtl configuration tool in Sun VirtualBox 3.0.x before 3.0.8 on Solaris x86, L
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.31-rc4 - 'nfs4_proc_lock()' Denial of Service
The nfs4_proc_lock function in fs/nfs/nfs4proc.c in the NFSv4 client in the Linux kernel before 2.6.31-rc4 allows remote
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Snitz Forums 2000 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Snitz Forums 2000 3.4.7 - Sound Tag Onload Attribute Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Snitz Forums 2000 3.4.7 - 'pop_send_to_friend.asp?url' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Rational RequisitePro 7.10 - ReqWeb Help Feature 'ReqWebHelp/basic/searchView.jsp' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM R
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BloofoxCMS 0.3.5 - 'search' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.5.html in BloofoxCMS 0.3.5 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Skybluecanvas 1.1 r237 - 'admin.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inj
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Rational RequisitePro 7.10 - 'ReqWeb Help Feature ReqWebHelp/advanced/workingSet.jsp?Operation' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM R
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Rational RequisitePro 7.10 / ReqWebHelp - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the ReqWeb Help feature (aka the Web Client Help system) in IBM R
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pentaho 1.7.0.1062 - Cross-Site Scripting / Information Disclosure
Multiple unspecified vulnerabilities in Pentaho Business Intelligence (BI) Suite before 1.2 RC3 (1.2.0.470-RC3) have unk
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dopewars Server 1.5.12 - 'REQUESTJET' Message Remote Denial of Service
Dopewars 1.5.12 allows remote attackers to cause a denial of service (segmentation fault) via a REQUESTJET message with
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6/7 - Memory Corruption (MS09-054)
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute ar
53RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Everfocus 1.4 - EDSR Remote Authentication Bypass
The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via ce
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DeDeCMS 5.1 - SQL Injection
SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Eclipse BIRT 2.2.1 - 'run?__report' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Achievo 1.3.4 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zainu 1.0 - 'searchSongKeyword' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Zainu 1.0 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZoIPer 2.22 - Call-Info Remote Denial of Service
ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Achievo 1.3.4 - SQL Injection
SQL injection vulnerability in the get_employee function in classweekreport.inc in Achievo before 1.4.0 allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Palm Pre WebOS 1.1 - Denial of Service
The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Achievo 1.x - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Achievo before 1.4.0 allow remote attackers to inject arbitrary w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dream Poll 3.1 - '/index.php' Cross-Site Scripting / SQL Injection
Multiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote attackers to execute arbit
23RIESGO
abrir ↗Metasploit400
Adobe U3D CLODProgressiveMeshDeclaration Array Overrun
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x befor
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - 'deflate' HTTP Content Encoding Remote Code Execution
Unspecified vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, and 7 allows remote attackers to execute ar
53RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Quick Heal 10.00 SP1 - Local Privilege Escalation
Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Fu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader 9.1.3 / Acrobat - COM Objects Memory Corruption Remote Code Execution
Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 allow attackers to cause a den
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.