Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.651Exploit-DB 24.485GitHub PoC 15.884VulnCheck XDB 9215Nuclei 4454Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.202 exploits
Exploit-DB✓ VexDay Proof
vicFTP 5.0 - 'LIST' Remote Denial of Service
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NU
50RIESGO
abrir ↗Metasploit300
Victory FTP Server 5.0 LIST DoS
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (fo
50RIESGO
abrir ↗Metasploit300
Victory FTP Server 5.0 LIST DoS
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NU
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 9.50/9.61 historysearch - Command Execution (Metasploit)
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - '.ty' Local Buffer Overflow (SEH)
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
UC Gateway Investment SiteEngine 5.0 - 'announcements.php' SQL Injection
SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Osprey 1.0a4.1 - 'ListRecords.php' Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0a4.1 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - 'liste' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/postlister/index.php in Jetbox CMS 2.1 allows remote attackers to inje
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MindDezign Photo Gallery 2.2 - SQL Injection
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ClipShare Pro 4.0 - 'fullscreen.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in fullscreen.php in ClipShare Pro 4.0 allows remote attackers to inject arbitr
23RIESGO
abrir ↗Metasploit600
Opera historysearch XSS
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - '.ty' Local Buffer Overflow (SEH)
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adam Wright HTMLTidy 0.5 - 'html-tidy-logic.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in includes/htmlArea/plugins/HtmlTidy/html-tidy-logic.php in Kayako eSupport 3.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
UC Gateway Investment SiteEngine 5.0 - 'api.php' Open Redirection
Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbi
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MindDezign Photo Gallery 2.2 - Arbitrary Add Admin
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir ↗Metasploit400
VideoLAN VLC TiVo Buffer Overflow
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir ↗Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_IPUBLISH.ALTER_HOTLOG_INTERNAL_CSOURCE
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RIESGO
abrir ↗Metasploit300
Oracle DB SQL Injection via SYS.LT.MERGEWORKSPACE
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RIESGO
abrir ↗Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_PUBLISH.ALTER_AUTOLOG_CHANGE_SOURCE
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dizi Portali - 'diziler.asp' SQL Injection
SQL injection vulnerability in diziler.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - '.TY' Local Stack Buffer Overflow
Multiple integer overflows in ty.c in the TY demux plugin (aka the TiVo demuxer) in VideoLAN VLC media player, probably
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bahar Download Script 2.0 - 'aspkat.asp' SQL Injection
SQL injection vulnerability in aspkat.asp in Bahar Download Script 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPhotoGallery 0.92 - 'index.php' SQL Injection
Multiple SQL injection vulnerabilities in index.php in phPhotoGallery 0.92 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.4 - '.TY' Local Stack Buffer Overflow
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - '/admin/cms/images.php?orderby' SQL Injection
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke Sarkilar Module - 'id' SQL Injection
SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jetbox CMS 2.1 - '/admin/cms/nav.php?nav_id' SQL Injection
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vivvo CMS 3.4 - Multiple Vulnerabilities
SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BitTorrent 6.0.3 - '.torrent' Local Stack Buffer Overflow
Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vivvo CMS 3.4 - Multiple Vulnerabilities
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 an
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.