Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Joomla! Component JE Guestbook 1.0 - Multiple Vulnerabilities
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JE Directory 1.0 - SQL Injection
SQL injection vulnerability in the JExtensions JE Directory (com_jedirectory) component 1.0 for Joomla! allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Getsimple CMS 2.01 - 'changedata.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - SxView Record Parsing Heap Memory Corruption
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML Fil
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MODx manager - '/controllers/default/resource/tvs.php?class_key' Traversal Local File Inclusion
Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possi
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyPhpAuction 2010 - 'id' SQL Injection
SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36-rc6 (RedHat / Ubuntu 10.04) - 'pktcdvd' Kernel Memory Disclosure
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Webspell 4.2.1 - 'asearch.php' SQL Injection
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XFS - Deleted Inode Local Information Disclosure
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode b
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MODx 2.0.2-pl - '/manager/index.php?modahsh' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inj
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - 'Winhlp32.exe' MsgBox Code Execution (MS10-023) (Metasploit)
vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft DNS RPC Service - 'extractQuotedChar()' Remote Overflow 'SMB' (MS07-029) (Metasploit)
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPMyFAQ 2.6.x - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Horde IMP Webmail 4.3.7 - 'fetchmailprefs.php' HTML Injection
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Ed
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Entrans - SQL Injection
SQL injection vulnerability in poll.php in Entrans 0.3.2 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MSHTML Findtext Processing
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Java - RMIConnectionImpl Deserialization Privilege Escalation (Metasploit)
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Cinepak Codec CVDecompress - Heap Overflow (MS10-055)
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Blue River Mura CMS - Directory Traversal
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
E-Xoopport Samsara 3.1 (eCal Module) - Blind SQL Injection
SQL injection vulnerability in location.php in the eCal module in E-Xoopport Samsara 3.1 and earlier allows remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Illustrator CS4 14.0.0 - Postscript (.eps) Buffer Overflow (Metasploit)
Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execu
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe CoolType - SING Table 'uniqueName' Local Stack Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' Cotent Buffer Overflow (Metasploit) (2)
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' compiled Buffer Overflow (Metasploit) (4)
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft PowerPoint Viewer - TextBytesAtom Stack Buffer Overflow (MS10-004) (Metasploit)
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code vi
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Basic - '.VBP' Local Buffer Overflow (Metasploit)
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DjVu - 'DjVu_ActiveX_MSOffice.dll' ActiveX Component Buffer Overflow (Metasploit)
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat - Bundled LibTIFF Integer Overflow (Metasploit)
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProShow Gold 4.0.2549 - '.psh' Local Stack Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (2)
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.