Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.651Exploit-DB 24.485GitHub PoC 15.884VulnCheck XDB 9215Nuclei 4454Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.202 exploits
Exploit-DB✓ VexDay Proof
PHPRecipeBook 2.24 - 'base_id' SQL Injection
SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Metasploit200
Belkin Bulldog Plus Web Service Buffer Overflow
Belkin Bulldog Plus Web Service Buffer Overflow
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TinXCMS 3.5 - 'rss.php' SQL Injection
SQL injection vulnerability in system/rss.php in TinX/cms 3.x before 3.5.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy File Sharing Web Server 4.8 - File Disclosure
Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 2.0.x - Nested 'window.print()' Denial of Service
Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sopcast SopCore Control - 'sopocx.ocx' Command Execution
Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
cURL/libcURL 7.19.3 - HTTP 'Location:' Redirect Security Bypass
The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZ-Blog beta1 - Delete All Posts / SQL Injection
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell eDirectory iMonitor - 'Accept-Language' Request Buffer Overflow (PoC)
Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allow
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Graugon PHP Article Publisher 1.0 - SQL Injection / Cookie Handling
Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'seccomp' System Call Security Bypass
The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Media Commands - '.m3u' Local Overwrite (SEH)
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZ-Blog beta1 - Delete All Posts / SQL Injection
Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Graugon PHP Article Publisher 1.0 - SQL Injection / Cookie Handling
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrativ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Document Library 1.0.1 - Arbitrary Change Admin
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Merak Media Player 3.2 - '.m3u' File Local Buffer Overflow (SEH)
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long strin
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NovaStor NovaNET 12 - 'DtbClsLogin()' Remote Stack Buffer Overflow
Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute ar
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HTC Touch - vCard over IP Denial of Service
HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consum
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Blogsa 1.0 - 'Widgets.aspx' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inj
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Irokez Blog 0.7.3.2 - Multiple Input Validation Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, al
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
djbdns 1.05 - Long Response Packet Remote Cache Poisoning
The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Orbit Downloader 2.8.4 - 'Hostname' Remote Buffer Overflow
Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote
50RIESGO
abrir ↗Metasploit300
POP Peeper v3.4 DATE Buffer Overflow
Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a
50RIESGO
abrir ↗Metasploit300
POP Peeper v3.4 UIDL Buffer Overflow
Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Websphere Application Server 6.1/7.0 - Administrative Console Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 bef
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSC 0.11.x - PKCS#11 Implementation Unauthorized Access
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data obj
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - Cloned Process 'CLONE_PARENT' Local Origin Validation
The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent pr
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.