Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.322exploits catalogados
38.524CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.711Exploit-DB 24.485GitHub PoC 15.927VulnCheck XDB 9231Nuclei 4455Metasploit 3513✓ solo verificadosrecientespopularesriesgo
82.322 exploits
Exploit-DB✓ VexDay Proof
Kantaris 0.3.4 - SSA Subtitle Local Buffer Overflow
The MP4 demuxer (mp4.c) for VLC media player 0.8.6d and earlier, as used in Miro Player 1.1 and earlier, allows remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kantaris 0.3.4 - SSA Subtitle Local Buffer Overflow
VLC before 0.8.6f allow remote attackers to cause a denial of service (crash) via a crafted Cinepak file that triggers a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kantaris 0.3.4 - SSA Subtitle Local Buffer Overflow
Integer overflow in the MP4_ReadBox_rdrf function in libmp4.c for VLC 0.8.6e allows remote attackers to cause a denial o
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kantaris 0.3.4 - SSA Subtitle Local Buffer Overflow
Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP serve
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kantaris 0.3.4 - SSA Subtitle Local Buffer Overflow
Stack-based buffer overflow in modules/demux/subtitle.c in VideoLAN VLC 0.8.6d allows remote attackers to execute arbitr
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Digital Hive 2.0 - 'base.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in base.php in DigitalHive 2.0 RC2 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Computer Associates ARCserve Backup Discovery Service Remote - Denial of Service
The Discovery Service (casdscvc) in CA ARCserve Backup 12.0.5454.0 and earlier allows remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHCDownload 1.1 - '/admin/index.php?hash' SQL Injection
SQL injection vulnerability in admin/index.php in PHCDownload 1.1 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus Expeditor 6.1 - URI Handler Command Execution
Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pixel Motion Blog - 'list_article.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in liste_article.php in Blog Pixel Motion (aka PixelMotion) allows remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Eclipse 3.3.2 IDE - 'Help Server help/advanced/workingSetManager.jsp?workingSet' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclips
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke DownloadsPlus Module - Arbitrary File Upload
Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Eclipse 3.3.2 IDE - 'Help Server help/advanced/searchView.jsp?SearchWord' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclips
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHCDownload 1.1 - '/upload/install/index.php?step' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to injec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Horde Webmail 1.0.6 - 'addevent.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in addevent.php in Horde Kronolith 2.1.7, Groupware Webmail Edition 1.0.6, and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
F5 Networks FirePass 4100 SSL VPN - 'installControl.php3' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in installControl.php3 in F5 FirePass 4100 SSL VPN 5.4.2-5.5.2 and 6.0-6.2 allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
S9Y Serendipity 1.3 - Referer HTTP Header Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Top Referrers (aka referrer) plugin in Serendipity (S9Y) before 1.3.1 al
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iCal 3.0.1 - 'ATTACH' Denial of Service
Use-after-free vulnerability in Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote atta
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iCal 3.0.1 - 'COUNT' Integer Overflow
Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of serv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XOOPS 2.0.14 Article Module - 'article.php' SQL Injection
SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PortailPHP 2.0 - 'mod_search' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Cedric CLAIRE PortailPhp 2 allow remote attackers to execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iCal 3.0.1 - 'TRIGGER' Denial of Service
Apple iCal 3.0.1 on Mac OS X allows remote CalDAV servers, and user-assisted remote attackers, to cause a denial of serv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advanced Electron Forum 1.0.6 - 'beg' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Advanced Electron Forum (AEF) 1.0.6 allows remote attackers to inject arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wikepage Opus 13 2007.2 - 'wiki' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Wikepage Opus 13 2007.2 allows remote attackers to inject arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TLM CMS 3.1 - Multiple SQL Injections
SQL injection vulnerability in TLM CMS 3.1 allows remote attackers to execute arbitrary SQL commands via the nom paramet
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
μTorrent (uTorrent) WebUI 0.310 Beta 2 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TorrentFlux 2.3 - 'admin.php' Cross-Site Request Forgery (Add Admin)
Cross-site request forgery (CSRF) vulnerability in html/admin.php in TorrentFlux 2.3 allows remote attackers to hijack t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.3.3 - 'cat' Directory Traversal
Directory traversal vulnerability in the get_category_template function in wp-includes/theme.php in WordPress 2.3.3 and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt 2.0 - 'adminler.asp' SQL Injection
SQL injection vulnerability in adminler.asp in CoBaLT 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyBoard 1.0.12 - 'rep.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in rep.php in Martin BOUCHER MyBoard 1.0.12 allows remote attackers to inject a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.