Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.651Exploit-DB 24.485GitHub PoC 15.884VulnCheck XDB 9215Nuclei 4454Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.202 exploits
Exploit-DB✓ VexDay Proof
Vivvo CMS 3.4 - Multiple Vulnerabilities
PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 an
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nuke ET 3.4 - 'FCKeditor' Arbitrary File Upload
Unknown vulnerability in FCKeditor 2.0 RC2, when used with PHP-Nuke, allows remote attackers to upload arbitrary files.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nuke ET 3.4 - 'FCKeditor' Arbitrary File Upload
Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FlashChat - 'connection.php' Role Filter Security Bypass
connection.php in FlashChat 5.0.8 allows remote attackers to bypass the role filter mechanism and gain administrative pr
23RIESGO
abrir ↗Metasploit600
Mantis manage_proj_page PHP Code Execution
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Habari 0.5.1 - 'habari_username' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the login feature in Habari CMS 0.5.1 allows remote attackers to inject arbi
23RIESGO
abrir ↗Metasploit600
Husdawg, LLC. System Requirements Lab ActiveX Unsafe Method
Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the downlo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook Web Access for Exchange Server 2003 - 'redir.asp' Open Redirection
Open redirect vulnerability in exchweb/bin/redir.asp in Microsoft Outlook Web Access (OWA) for Exchange Server 2003 SP2
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris sadmind adm_build_path - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allo
50RIESGO
abrir ↗Metasploit500
Sun Solaris sadmind adm_build_path() Buffer Overflow
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allo
50RIESGO
abrir ↗Metasploit300
Microsoft Host Integration Server 2006 Command Execution Vulnerability
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, whic
40RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 0.9.2 Media Player - XSPF Memory Corruption
Array index error in VLC media player 0.9.2 allows remote attackers to overwrite arbitrary memory and execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Elxis CMS 2008.1 - '/modules/mod_language.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in Elxis CMS 2008.1 revision 2204 allows remote attackers to injec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nuked-klaN 1.7.7 / SP4.4 - Multiple Vulnerabilities
SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forw
23RIESGO
abrir ↗Metasploit300
Titan FTP Server 6.26.630 SITE WHO DoS
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Elxis CMS 2008.1 - PHPSESSID Variable Session Fixation
Session fixation vulnerability in Elxis CMS 2008.1 revision 2204 allows remote attackers to hijack web sessions by setti
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Database Server 11.1 - 'CREATE ANY Directory' Privilege Escalation
Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased i
23RIESGO
abrir ↗Metasploit300
Oracle DB SQL Injection via SYS.LT.REMOVEWORKSPACE
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RIESGO
abrir ↗Metasploit300
XM Easy Personal FTP Server 5.6.0 NLST DoS
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RIESGO
abrir ↗Metasploit300
Oracle DB SQL Injection via SYS.LT.COMPRESSWORKSPACE
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LokiCMS 0.3.4 - 'writeconfig()' Remote Command Execution
LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASP Indir Iltaweb Alisveris Sistemi - 'xurunler.asp' SQL Injection
SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Metasploit300
Guild FTPd 0.999.8.11/0.999.14 Heap Corruption
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Proxim Tsunami MP.11 2411 Wireless Access Point - 'system.sysName.0' SNMP HTML Injection
Cross-site scripting (XSS) vulnerability in the Proxim Wireless Tsunami MP.11 2411 with firmware 3.0.3 allows remote aut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - GDI+ (PoC) (MS08-052) (2)
gdiplus.dll in GDI+ in Microsoft Internet Explorer 6 SP1, Windows XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold an
35RIESGO
abrir ↗Metasploit200
Computer Associates ARCserve REPORTREMOTEEXECUTECML Buffer Overflow
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS 1.3.7 - 'HP-GL/2' Filter Remote Code Execution
The Hewlett-Packard Graphics Language (HPGL) filter in CUPS before 1.3.9 allows remote attackers to execute arbitrary co
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GForge 4.5.19 - Multiple SQL Injections
SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset pa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HispaH textlinksads - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Konqueror 3.5.9 - 'color'/'bgcolor' Multiple Remote Crash Vulnerabilities
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a fo
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.