Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.419exploits catalogados
38.564CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.745Exploit-DB 24.485GitHub PoC 15.945VulnCheck XDB 9270Nuclei 4456Metasploit 3518✓ solo verificadosrecientespopularesriesgo
82.419 exploits
Exploit-DB✓ VexDay Proof
RaidenHTTPD 2.0.19 - 'ulang' Remote Command Execution
Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RavWare Software - '.MAS' Flic Control Remote Buffer Overflow
Buffer overflow in RavWare Software MAS Flic ActiveX Control (masflc.ocx) 1.0.0.1 allows remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iMesh 7.1.0.x - 'IMWeb.dll 7.0.0.x' Remote Heap Overflow
The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player 7.0.x/8.0.x/9.0.x - ActiveX Control 'navigateToURL' API Cross Domain Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player 8.0.34.0/9.0.x - 'main.swf?baseurl' asfunction: Protocol Handler Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Adobe Flash Player 9.x up to 9.0.48.0 and 8.x up to 8.0.35.0 allo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PeerCast 0.12 - HandshakeHTTP Multiple Buffer Overflow Vulnerabilities
Heap-based buffer overflow in the handshakeHTTP function in servhs.cpp in PeerCast 0.1217 and earlier, and SVN 344 and e
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iMesh 7 - 'IMWebControl' ActiveX Control Code Execution
The IMWeb.IMWebControl.1 ActiveX control in IMWeb.dll 7.0.0.x, and possibly IMWebControl.dll, in iMesh 7.1.0.x and earli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Appian Business Process Management Suite 5.6 - Remote Denial of Service
Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers t
50RIESGO
abrir ↗Metasploit300
Appian Enterprise Business Suite 5.6 SP1 DoS
Unspecified vulnerability in Appian Enterprise Business Process Management (BPM) Suite 5.6 SP1 allows remote attackers t
50RIESGO
abrir ↗Metasploit600
Apple OS X Software Update Command Execution
Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Perl Net::DNS 0.48/0.59/0.60 - DNS Response Remote Denial of Service
Net/DNS/RR/A.pm in Net::DNS 0.60 build 654, as used in packages such as SpamAssassin and OTRS, allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phPay 2.2.1 - Windows Installations Local File Inclusion
Incomplete blacklist vulnerability in main.php in phPay 2.02.01 on Windows allows remote attackers to conduct directory
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
wwwstats 3.21 - 'Clickstats.php' Multiple HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in clickstats.php in wwwstats 3.21 allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpRPG 0.8 - '/tmp' Directory PHPSESSID Cookie Session Hijacking
phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 3.0.27a - 'send_mailslot()' Remote Buffer Overflow
Stack-based buffer overflow in the send_mailslot function in nmbd in Samba 3.0.0 through 3.0.27a, when the "domain logon
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MKPortal 1.1 Gallery Module - SQL Injection
SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX xnu 1228.0 - 'super_blob' Local kernel Denial of Service (PoC)
The cs_validate_page function in bsd/kern/ubc_subr.c in the xnu kernel 1228.0 and earlier in Apple Mac OS X 10.5.1 allow
23RIESGO
abrir ↗Metasploit300
MS07-064 Microsoft DirectX DirectShow SAMI Buffer Overflow
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RIESGO
abrir ↗Metasploit400
MS07-065 Microsoft Message Queueing Service DNS Name Path Overflow
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SquirrelMail G/PGP Encryption Plugin - 'deletekey()' Command Injection
The G/PGP (GPG) Plugin 2.1 and earlier for Squirrelmail allow remote authenticated users to execute arbitrary commands v
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.3.1 - Charset SQL Injection
SQL injection vulnerability in wp-includes/query.php in WordPress 2.3.1 and earlier allows remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
barracudadrive 3.7.2 - Multiple Vulnerabilities
Group Chat in BarracudaDrive Web Server before 3.8 allows remote authenticated users to cause a denial of service (crash
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
barracudadrive 3.7.2 - Multiple Vulnerabilities
BarracudaDrive Web Server before 3.8 allows remote attackers to read the source code for web scripts by appending a (1)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
barracudadrive 3.7.2 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read
23RIESGO
abrir ↗Metasploit500
BadBlue 2.72b PassThru Buffer Overflow
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
E-Xoops 1.0.5/1.0.8 - '/adresses/ratefile.php?lid' SQL Injection
Multiple SQL injection vulnerabilities in e-Xoops (exoops) 1.08, and 1.05 Rev 1 through 3, allow remote attackers to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BadBlue 2.72b - Multiple Vulnerabilities
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BadBlue 2.72b - Multiple Vulnerabilities
BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
webSPELL 4.1.2 - 'calendar.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in webSPELL 4.1.2 allow remote attackers to inject arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
barracudadrive 3.7.2 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbit
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.