Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.651Exploit-DB 24.485GitHub PoC 15.884VulnCheck XDB 9215Nuclei 4454Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.202 exploits
Exploit-DB✓ VexDay Proof
X-BLC 0.2.0 - 'get_read.php?section' SQL Injection
SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sysax Multi Server 4.3 - Arbitrary Delete Files Expoit
Directory traversal vulnerability in Sysax Multi Server 4.3 and 4.5 allows remote authenticated users to delete arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zinf Audio Player 2.2.1 - '.pls' Universal Overwrite (SEH)
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ExpressionEngine 1.6 - Avtaar Name HTML Injection
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Racer 0.5.3 Beta 5 - Remote Stack Buffer Overflow
Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xlight FTP Server 3.2 - 'user' SQL Injection
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DeluxeBB 1.3 - 'qorder' SQL Injection
SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir ↗Metasploit300
Talkative IRC v0.4.4.16 Response Buffer Overflow
Talkative IRC v0.4.4.16 Response Buffer Overflow
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YAP 1.1.1 - 'index.php' Local File Inclusion
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foxit Reader 3.0 (Build 1301) - PDF Universal Buffer Overflow
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to e
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpmysport 1.4 - Cross-Site Scripting / SQL Injection
Multiple SQL injection vulnerabilities in index.php in phpMySport 1.4, when magic_quotes_gpc is disabled, allow remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TikiWiki 2.2/3.0 - 'tiki-galleries.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TikiWiki 2.2/3.0 - 'tiki-listpages.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SlySoft (Multiple Products) - Driver IOCTL Request Multiple Local Buffer Overflow Vulnerabilities
Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TikiWiki 2.2/3.0 - 'tiki-list_file_gallery.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PostgreSQL 8.3.6 - Conversion Encoding Remote Denial of Service
PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of servi
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun xVM VirtualBox 2.0/2.1 - Local Privilege Escalation
Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CMS WEBjump! - Multiple SQL Injections
SQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Metasploit600
IBM System Director Agent DLL Injection
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NextApp Echo < 2.1.1 - XML Injection
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a req
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM System Director Agent 5.20 - CIM Server Privilege Escalation
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
woltlab burning board 3.0.x - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPRecipeBook 2.24 - 'base_id' SQL Injection
SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHORTAIL 1.2.1 - 'poster.php' Multiple HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
nForum 1.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1
23RIESGO
abrir ↗Metasploit400
eZip Wizard 3.0 Stack Buffer Overflow
Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .z
50RIESGO
abrir ↗Metasploit300
Foxit Reader Authorization Bypass
Foxit Reader 2.3 before Build 3902 and 3.0 before Build 1506, including 1120 and 1301, does not require user confirmatio
30RIESGO
abrir ↗Metasploit400
Foxit Reader 3.0 Open Execute Action Stack Based Buffer Overflow
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to e
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Fusion Mod Book Panel - 'bookid' SQL Injection
SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EO Video 1.36 - Playlist Overwrite (SEH)
Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (applicatio
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.