Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.596exploits catalogados
36.656CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.212GitHub PoC 15.164VulnCheck XDB 8883Nuclei 4369Metasploit 3493✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
klinza Professional CMS 5.0.1 - 'menulast.php' Local File Inclusion
Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Quick.Cart 3.4 / Quick.CMS 2.4 - Delete Function Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authen
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.10 - APPE DELE Denial of Service
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (appen
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
outreach project tool 1.2.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - SELECT Statement WHERE Clause Sub-query Denial of Service
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Autodesk Maya Script - Nodes Arbitrary Command Execution
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - 'GeomFromWKB()' Function First Argument Geometry Value Handling Denial of Service
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Autodesk SoftImage 7.0 Scene - '.TOC' File Remote Code Execution
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Autodesk SoftImage Scene TOC - Arbitrary Command Execution
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Com_Joomclip - 'cat' SQL Injection
SQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Betsy CMS versions 3.5 - Local File Inclusion
Directory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.x - 'graph.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AIMP2 Audio Converter 2.53 build 330 - Playlist '.pls' Unicode Buffer Overflow
Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a den
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TEKUVA - Password Reminder Authentication Bypass
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco VPN Client - Integer Overflow Denial of Service
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera Web Browser 10.01 - 'dtoa()' Remote Code Execution
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE 4.3.3 - KDELibs 'dtoa()' Remote Code Execution
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SeaMonkey 1.1.8 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
K-Meleon 1.5.3 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 10.01 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE KDELibs 4.3.3 - Remote Array Overrun
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CubeCart 3.0.4/4.3.6 - 'ProductID' SQL Injection
SQL injection vulnerability in includes/content/viewProd.inc.php in CubeCart before 4.3.7 remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM SolidDB - Invalid Error Code
The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Extension iF Portfolio Nexus - SQL Injection
SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xerver 4.31/4.32 - HTTP Response Splitting
CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP header
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Shoutbox 1.0 - HTML / Cross-Site Scripting Injection
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Plohni Shoutbox 1.0 allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ActiveBids - 'default.asp' Blind SQL Injection
Multiple SQL injection vulnerabilities in ActiveWebSoftwares Active Bids allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Home FTP Server - 'MKD' Directory Traversal
Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) creat
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JiRo's (Multiple Products) - '/files/login.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in files/login.asp in JiRo's Banner System eXperience (JBSX) allow remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Avast! 4.8.1351.0 AntiVirus - 'aswMon2.sys' Kernel Memory Corruption
Stack-based buffer overflow in aswMon2.sys in avast! Home and Professional for Windows 4.8.1351, and possibly other vers
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.