Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.651Exploit-DB 24.485GitHub PoC 15.884VulnCheck XDB 9215Nuclei 4454Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.202 exploits
Exploit-DB✓ VexDay Proof
Sun Java System Calendar Server 6 - 'command.shtml' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 an
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Community CMS 0.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Turnkey eBook Store 1.1 - 'keywords' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbit
23RIESGO
abrir ↗Metasploit300
SAP AG SAPgui EAI WebViewer3D Buffer Overflow
Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Leve
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP MaxDB 7.4/7.6 - 'webdbm' Multiple Cross-Site Scripting Vulnerabilities
Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Leve
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPRecipeBook 2.39 - 'course_id' SQL Injection
SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
family connection 1.8.1 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AtomixMP3 < 2.3 - 'Playlist' Universal Overwrite (SEH)
Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in fil
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JobHut 1.2 - 'pk' SQL Injection
SQL injection vulnerability in browse.php in JobHut 1.2 and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Diskos CMS Manager - SQL Injection / File Disclosure / Authentication Bypass
Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BandSite CMS 1.1.4 - 'members.php' SQL Injection
Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authentic
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Diskos CMS Manager - SQL Injection / File Disclosure / Authentication Bypass
Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BandSite CMS 1.1.4 - 'members.php' SQL Injection
SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
glFusion 1.1.2 - 'COM_applyFilter()/order' SQL Injection
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iWare CMS 5.0.4 - Multiple SQL Injections
SQL injection vulnerability in index.php in iWare Professional 5.0.4, when magic_quotes_gpc is disabled, allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pam-krb5 < 3.13 - Local Privilege Escalation
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.7.0 - 'NLST' Denial of Service
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RIESGO
abrir ↗Metasploit300
XM Easy Personal FTP Server 5.7.0 NLST DoS
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
freeSSHd 1.2.1 - 'rename' Remote Buffer Overflow (SEH)
Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and ex
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft GdiPlus - EMF GpFont.SetData Integer Overflow (PoC)
Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Femitter FTP Server 1.x - (Authenticated) Multiple Vulnerabilities
The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending
23RIESGO
abrir ↗Metasploit300
IBM Access Support ActiveX Control Buffer Overflow
Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as dist
50RIESGO
abrir ↗Metasploit600
phpMyAdmin Config File Code Injection
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RIESGO
abrir ↗Metasploit600
phpMyAdmin Config File Code Injection
Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x be
23RIESGO
abrir ↗Metasploit400
Adobe Collab.getIcon() Buffer Overflow
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jinzora Media Jukebox 2.8 - 'name' Local File Inclusion
Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to inclu
23RIESGO
abrir ↗Metasploit400
Adobe Collab.getIcon() Buffer Overflow
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
X-BLC 0.2.0 - 'get_read.php?section' SQL Injection
SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zinf Audio Player 2.2.1 - '.pls' Universal Overwrite (SEH)
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Codice CMS 2 - Command Execution (via SQL Injection)
SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.