Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.651Exploit-DB 24.485GitHub PoC 15.884VulnCheck XDB 9215Nuclei 4454Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.202 exploits
Metasploit300
Avahi Source Port 0 DoS
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 al
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Active Directory LDAP Server - 'Username' Enumeration
The LDAP server in Active Directory in Microsoft Windows 2000 SP4 and Server 2003 SP1 and SP2 responds differently to a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alstrasoft Web Host Directory 1.2 - Multiple Vulnerabilities
SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Recipes Listing Portal - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Auto Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Auto Classifieds Software - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execut
23RIESGO
abrir ↗Metasploit300
Pi3Web ISAPI DoS
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ScriptsFeed (SF) Recipes Listing Portal - Arbitrary File Upload
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netgear WGR614 - Administration Interface Remote Denial of Service
The web management interface in Netgear WGR614v9 allows remote attackers to cause a denial of service (crash) via a requ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Net-SNMP 5.1.4/5.2.4/5.4.1 Perl Module - Buffer Overflow (PoC)
Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zope 2.11.2 - PythonScript Multiple Remote Denial of Service Vulnerabilities
PythonScripts in Zope 2 2.11.2 and earlier, as used in Conga and other products, allows remote authenticated users to ca
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Castle Rock Computing SNMPc < 7.1.1 - 'Community' Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the Network Manager in Castle Rock Computing SNMPc 7.1 and earlier allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yosemite Backup 8.70 - 'DtbClsLogin()' Remote Buffer Overflow
Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute ar
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Simple RSS Reader 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component fo
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_marketplace 1.2.1 - 'catid' SQL Injection
SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla!
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java System Identity Manager 6.0/7.x - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 al
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OTManager CMS 2.4 - 'Tipo' Remote File Inclusion
PHP remote file inclusion vulnerability in Admin/ADM_Pagina.php in OTManager 2.4 allows remote attackers to execute arbi
23RIESGO
abrir ↗Metasploit600
Openfire Admin Console Authentication Bypass
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JooBlog 0.1.1 - 'PostID' SQL Injection
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dizi Portali - 'film.asp' SQL Injection
SQL injection vulnerability in film.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Vista/2003 - 'UnhookWindowsHookEx' Local Denial of Service
Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zeeways Shaadi Clone 2.0 - Authentication Bypass (2)
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
V3 Chat Live Support 3.0.4 - Insecure Cookie Handling
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
V3 Chat Profiles/Dating Script 3.0.2 - Insecure Cookie Handling
admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyioSoft EasyBookMarker 4.0 - Authentication Bypass
Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Myiosoft EasyBookMarker 4 - 'Parent' SQL Injection
Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Anti-Trojan Elite 4.2.1 - 'Atepmon.sys' IOCTL Request Local Overflow / Local Privilege Escalation
Buffer overflow in Atepmon.sys in ISecSoft Anti-Trojan Elite 4.2.1 and earlier, and possibly 4.2.2, allows local users t
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.