Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.419exploits catalogados
38.564CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.745Exploit-DB 24.485GitHub PoC 15.945VulnCheck XDB 9270Nuclei 4456Metasploit 3518✓ solo verificadosrecientespopularesriesgo
82.419 exploits
Exploit-DB✓ VexDay Proof
Joomla! Component panoramic 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in admin.panoramic.php in the Panoramic Picture Viewer (com_panoramic) mambot (p
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Else If CMS 0.6 - Multiple Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Else If CMS 0.6 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in ELSEIF CMS Beta 0.6 allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Else If CMS 0.6 - Multiple Vulnerabilities
ELSEIF CMS Beta 0.6 allows remote attackers to obtain sensitive information (full path) via unspecified vectors to utili
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Else If CMS 0.6 - Multiple Vulnerabilities
ELSEIF CMS Beta 0.6 does not properly unset variables when the input data includes a numeric parameter with a value matc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pegasus Imaging ImagXpress 8.0 - Arbitrary File Overwrite
Multiple absolute path traversal vulnerabilities in Pegasus Imaging ImagXpress 8.0 allow remote attackers to (1) delete
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AfterLogic MailBee WebMail Pro 3.x - 'default.asp?mode2' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AfterLogic MailBee WebMail Pro 3.x - 'login.php?mode' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MailBee WebMail Pro 3.4 and earlier; and possibly MailBee WebMail
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dawn of Time 1.69 MUD Server - Multiple Format String Vulnerabilities
Multiple format string vulnerabilities in websrv.cpp in Dawn of Time 1.69s beta4 and earlier allow remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - URI Handler Command Execution
The URL handling in Shell32.dll in the Windows shell in Microsoft Windows XP and Server 2003, with Internet Explorer 7 i
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DropTeam 1.3.3 - Multiple Remote Vulnerabilities
Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which all
23RIESGO
abrir ↗Metasploit600
HPLIP hpssd.py From Address Arbitrary Command Execution
hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cart32 6.x - GetImage Arbitrary File Download
c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName par
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Google FeedBurner FeedSmith 2.2 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the FeedBurner FeedSmith 2.2 plugin for WordPress allows remote attac
23RIESGO
abrir ↗Metasploit400
Borland InterBase PWD_db_aliased() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Metasploit400
Borland InterBase isc_attach_database() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Metasploit400
Borland InterBase open_marker_file() Buffer Overflow
Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versio
50RIESGO
abrir ↗Metasploit400
Borland InterBase INET_connect() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Metasploit400
Borland InterBase SVC_attach() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Metasploit400
Borland InterBase isc_create_database() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Metasploit400
Borland InterBase jrd8_create_database() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Borland Interbase 2007/2007 SP2 - 'INET_connect' Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Borland Interbase 2007/2007 SP2 - 'open_marker_file' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in Borland InterBase LI 8.0.0.53 through 8.1.0.253 on Linux, and possibly unspecified versio
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DRBGuestbook 1.1.13 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Don Barnes DRBGuestbook 1.1.13 allows remote attackers to injec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Borland Interbase 2007/2007 SP2 - 'jrd8_create_database' Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Metasploit300
Kazaa Altnet Download Manager ActiveX Control Buffer Overflow
Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) K
43RIESGO
abrir ↗Metasploit200
Firebird Relational Database SVC_attach() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Metasploit200
Firebird Relational Database isc_create_database() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Metasploit200
Firebird Relational Database isc_attach_database() Buffer Overflow
Multiple stack-based buffer overflows in Borland InterBase LI 8.0.0.53 through 8.1.0.253, and WI 5.1.1.680 through 8.1.0
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Content Builder 0.7.5 - 'postComment.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.