Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Horde Application Framework 3.3.8 - 'icon_browser.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in util/icon_browser.php in the Horde Application Framework before 3.3.9 allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySource Matrix - 'char_map.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'webappmon.exe execvp_nc' Remote Code Execution
Stack-based buffer overflow in the execvp_nc function in the ov.dll module in HP OpenView Network Node Manager (OV NNM)
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Aardvertiser 2.1 - Blind SQL Injection
SQL injection vulnerability in the Aardvertiser (com_aardvertiser) component 2.1 and 2.1.1 for Joomla! allows remote att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Micronetsoft RV Dealer Website - SQL Injection
SQL injection vulnerability in detail.asp in Micronetsoft RV Dealer Website 1.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Softbiz Article Directory Script - 'sbiz_id' Blind SQL Injection
SQL injection vulnerability in article_details.php in Softbiz Article Directory Script allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
A-Blog 2.0 - '/sources/search.php' SQL Injection
SQL injection vulnerability in sources/search.php in A-Blog 2.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft MPEG Layer-3 - Remote Command Execution
Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Se
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DMXready Polling Booth Manager - SQL Injection
SQL injection vulnerability in inc_pollingboothmanager.asp in DMXReady Polling Booth Manager allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ChillyCMS 1.1.3 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to inject arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ChillyCMS 1.1.3 - Multiple Vulnerabilities
SQL injection vulnerability in core/showsite.php in chillyCMS 1.1.3 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Movie Maker - Remote Code Execution (MS10-016)
Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 3.3.12 (Linux x86) - 'chain_reply' Memory Corruption (Metasploit)
Buffer overflow in the SMB1 packet chaining implementation in the chain_reply function in process.c in smbd in Samba 3.0
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Classifieds ADS - 'sid' Blind SQL Injection
SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NuSOAP 0.9.5 - 'nusoap.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime FlashPix NumberOfTiles - Remote Code Execution
Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CMS WebManager-Pro - 'c.php' SQL Injection
SQL injection vulnerability in c.php in CMS WebManager-Pro before 8.1 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OneCMS 2.6.1 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader and Flash Player - 'newclass' Invalid Pointer
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mBlogger 1.0.04 - 'viewpost.php' SQL Injection
SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'custom.php?testmode' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'survey.php?category' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'idstatusframe.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'parameters.php?device' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'globals.php?tabpage' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component JE FAQ Pro 1.5.0 - Multiple Blind SQL Injections
Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime - '_Marshaled_pUnk' Backdoor Client-Side Arbitrary Code Execution
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions all
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Plug and Play Service - Overflow (MS05-039) (Metasploit)
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component PicSell 1.0 - Local File Disclosure
Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagull 0.6.7 - SQL Injection
SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.