Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
TechSmith Snagit 10 (Build 788) - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in TechSmith Snagit all versions 10.x and 11.x allows local users, and possibly remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Address Book 6.00.2900.5512 - 'wab32res.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xitami Web Server 2.5c2 - If-Modified-Since Overflow (Metasploit)
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Corel PHOTO-PAINT X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CorelDRAW X3 13.0.0.576 - 'crlrib.dll' DLL Hijacking
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Internet Communication Settings - 'schannel.dll' DLL Hijacking
Untrusted search path vulnerability in Microsoft Windows Internet Communication Settings on Windows XP SP3 allows local
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft RRAS Service - RASMAN Registry Overflow (MS06-025) (Metasploit)
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Serve
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mercur Messaging 2005 - IMAP Login Buffer Overflow (Metasploit)
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Object Type (MS03-020) (Metasploit)
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6.8 - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 an
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 10.61 - 'dwmapi.dll' DLL Hijacking
Untrusted search path vulnerability in Opera before 10.62 allows local users to gain privileges via a Trojan horse dwmap
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
μTorrent (uTorrent) 2.0.3 - 'plugin_dll.dll' DLL Hijacking
Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark 1.2.10 - 'airpcap.dll' DLL Hijacking
Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MicroP 0.1.1.1600 - 'mppl' Local Buffer Overflow
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Auto CMS 1.6 - 'autocms.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in autocms.php in Auto CMS 1.6 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle MySQL < 5.1.49 - Malformed 'BINLOG' Arguments Denial of Service
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle MySQL 5.1.48 - 'HANDLER' Interface Denial of Service
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysq
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OraclMySQL 5.1.48 - 'LOAD DATA INFILE' Denial of Service
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL err
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 5.1.48 - 'EXPLAIN' Denial of Service
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mys
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.7 (RedHat High Performance Computing [HPC]) - 'utilities.php?Filter' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - 'mbufs()' sendfile Cache Poisoning Privilege Escalation
FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, whi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Flock Browser 3.0.0 - Malformed Bookmark HTML Injection
Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 5.1.48 - 'Temporary InnoDB' Tables Denial of Service
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by c
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 3.0.20 < 3.0.25rc3 - 'Username' map script' Command Execution (Metasploit)
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free Simple Software 1.0 - Remote File Inclusion
SQL injection vulnerability in the download module in Free Simple Software 1.0 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free Simple Software 1.0 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k!GreStretchBltInternal() Does Not Handle src == dest
The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - nt!NtCreateThread Race Condition with Invalid Code Segment (MS10-047)
Race condition in the kernel in Microsoft Windows XP SP3 allows local users to gain privileges via vectors involving thr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - nt!SeObjectCreateSaclAccessBits() Missed ACE Bounds Checks (MS10-047)
The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free Simple Software 1.0 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.