Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.651Exploit-DB 24.485GitHub PoC 15.884VulnCheck XDB 9215Nuclei 4454Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.202 exploits
Exploit-DB✓ VexDay Proof
YourFreeWorld Banner Management - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourFreeWorld Banner Management - SQL Injection
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GE Fanuc Real Time Information Portal 2.6 - 'writeFile()' API (Metasploit)
Unrestricted file upload vulnerability in GE Fanuc Proficy Real-Time Information Portal 2.6 and earlier allows remote at
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourFreeWorld Short Url & Url Tracker - SQL Injection
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.9.3 - 'links.php' SQL Injection
SQL injection vulnerability in links.php in Appalachian State University phpWebSite allows remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Logz podcast CMS 1.3.1 - 'art' SQL Injection
Cross-site scripting (XSS) vulnerability in fichiers/add_url.php in Logz CMS 1.3.1 allows remote attackers to inject arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tribiq CMS 5.0.10a (Windows) - Local File Inclusion
Cross-site scripting (XSS) vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dovecot 1.1.x - Invalid Message Address Parsing Denial of Service
The message parsing feature in Dovecot 1.1.4 and 1.1.5, when using the FETCH ENVELOPE command in the IMAP client, allows
23RIESGO
abrir ↗Metasploit100
DjVu DjVu_ActiveX_MSOffice.dll ActiveX ComponentBuffer Overflow
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera Web Browser 9.x - History Search and Links Panel Cross-Site Scripting
The links panel in Opera before 9.62 processes Javascript within the context of the "outermost page" of a frame, which a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft DebugDiag 1.0 - 'CrashHangExt.dll' ActiveX Control Remote Denial of Service
The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attack
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SonicWALL - Content Filtering Blocked Site Error Page Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SonicWALL SonicOS Enhanced before 4.0.1.1, as used in SonicWALL Pro 2040 and
23RIESGO
abrir ↗Metasploit300
PacketTrap TFTP Server 2.2.5459.0 DoS
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of s
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PacketTrap TFTPD 2.2.5459.0 - Remote Denial of Service
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of s
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KKE Info Media Kmita Gallery - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Kmita Gallery allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Extrakt Framework 0.7 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Extrakt Framework 0.7 allows remote attackers to inject arbitra
23RIESGO
abrir ↗Metasploit500
MS08-067 Microsoft Server Service Relative Path Stack Corruption
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗Metasploit400
TugZip 3.5 Zip File Parsing Buffer Overflow Vulnerability
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Elkagroup Image Gallery 1.0 - 'view.php' SQL Injection
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
H&H Solutions WebSoccer 2.80 - 'id' SQL Injection
SQL injection vulnerability in liga.php in H&H WebSoccer 2.80 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke Nuke League Module - 'tid' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inj
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KKE Info Media Kmita Catalogue 2 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in Kmita Catalogue 2.x allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - ' ' Address Bar URI Spoofing
Visual truncation vulnerability in Microsoft Internet Explorer 6 allows remote attackers to spoof the address bar via a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Python 2.5.2 - 'Imageop' Module Argument Validation Buffer Overflow
Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent atta
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
bcoos 1.0.13 - 'click.php' SQL Injection
SQL injection vulnerability in modules/banners/click.php in the banners module for bcoos 1.0.10 allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 3.0.1 - 'pmd_pdf.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in pmd_pdf.php in phpMyAdmin 3.0.0, and possibly other versions including 2.11.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
All In One 1.4 Control Panel - 'cp_polls_results.php' SQL Injection
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.22 - 'ftruncate()'/'open()' Local Privilege Escalation
fs/open.c in the Linux kernel before 2.6.22 does not properly strip setuid and setgid bits when there is a write to a fi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java Web Start 1.0/1.2 - Remote Command Execution
The BasicService in Sun Java Web Start allows remote attackers to execute arbitrary programs on a client machine via a f
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iPeGuestbook 1.7/2.0 - 'pg' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in iPei Guestbook 2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.