Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Apple Mac OSX EvoCam Web Server - GET Buffer Overflow (Metasploit)
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
hplip - 'hpssd.py' From Address Arbitrary Command Execution (Metasploit)
hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ClamAV Milter - Blackhole-Mode Remote Code Execution (Metasploit)
clamav-milter in ClamAV before 0.91.2, when run in black hole mode, allows remote attackers to execute arbitrary command
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Community Builder Enhanced (CBE) 1.4.8/1.4.9/1.4.10 - Local File Inclusion / Remote Code Execution
Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 f
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
xWeblog 2.2 - 'arsiv.asp?tarih' SQL Injection
SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Flex Timesheet - Authentication Bypass
Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OPEN IT OverLook 5 - 'title.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
xWeblog 2.2 - 'oku.asp?makale_id' SQL Injection
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX LPD - Command Execution (Metasploit)
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of ser
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Club Manager - 'cm_id' SQL Injection
SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat and Reader - Array Indexing Remote Code Execution
Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execut
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft ASP.NET - Padding Oracle (MS10-070)
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Intern
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch WS_FTP Server 5.03 - MKD Overflow (Metasploit)
Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SlimFTPd - 'LIST' Concatenation Overflow (Metasploit)
Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alcatel-Lucent OmniPCX Enterprise - masterCGI Arbitrary Command Execution (Metasploit)
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows rem
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GlobalScape Secure FTP Server - Input Overflow (Metasploit)
Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetTerm NetFTPD - 'USER' Remote Buffer Overflow (Metasploit)
Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long US
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Workstation Service - NetpManageIPCConnect Overflow (MS06-070) (Metasploit)
Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Wi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9i XDB (Windows x86) - FTP UNLOCK Overflow (Metasploit)
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft DirectX DirectShow - SAMI Buffer Overflow (MS07-064) (Metasploit)
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DNET Live-Stats 0.8 - Local File Inclusion
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary fi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - 'pseudofs' Null Pointer Dereference Privilege Escalation
The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Savant Web Server 3.1 - Remote Overflow (Metasploit)
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Surgemail SurgeWeb 4.3e - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SmarterMail < 7.2.3925 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SmarterMail < 7.2.3925 - LDAP Injection
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 6.0 - ASP Stack Overflow Stack Exhaustion (Denial of Service) (MS10-065)
Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chipmunk Board 1.3 - 'index.php?forumID' SQL Injection
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Internet Security Pro 2010 - ActiveX 'extSetOwner()' Remote Code Execution (Metasploit)
The extSetOwner function in the UfProxyBrowserCtrl ActiveX control (UfPBCtrl.dll) in Trend Micro Internet Security Pro 2
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JE Guestbook 1.0 - Multiple Vulnerabilities
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to e
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.