Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
formmail 1.92 - Multiple Vulnerabilities
CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netgear DG632 Router - Authentication Bypass
The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentic
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 11.1 - Database Network Foundation Heap Memory Corruption
Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated us
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle WebLogic Server 10.3 - 'console-help.portal' Cross-Site Scripting
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9i/10g Database - TNS Command Remote Denial of Service
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Scriptsez Easy Image Downloader - 'id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9i/10g Database - Remote Network Authentication
Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9i/10g Database - Network Foundation Remote Overflow
Unspecified vulnerability in the Network Foundation component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4,
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 10g Secure Enterprise Search - 'search_p_groups' Cross-Site Scripting
Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP ProCurve Threat Management Services - zl ST.1.0.090213 Module CRL Security Bypass
Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
School Data Navigator - 'page' Local/Remote File Inclusion
PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Desi Short URL Script - (Authentication Bypass) Insecure Cookie Handling
index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_vehiclemanager 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_media_library 1.5.3 - Remote File Inclusion
PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component BookLibrary 1.5.2.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component com_realestatemanager 1.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Akobook 2.3 - 'gbid' SQL Injection
SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mrcgiguy the ticket system 2.0 PHP - Multiple Vulnerabilities
SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Cached Content Cross Domain Information Disclosure
Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vist
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Computer Associates SiteMinder - Unicode Cross-Site Scripting Protection Security Bypass
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Winds3D Viewer 3 - 'GetURL()' Arbitrary File Download
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Interlogy Profile Manager Basic - Insecure Cookie Handling
Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Computer Associates SiteMinder - '%00' Cross-Site Scripting Protection Security Bypass
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 5.0.75 - 'sql_parse.cc' Multiple Format String Vulnerabilities
Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ClanSphere 2009 - 'text' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Avax Vector 1.3 - 'avPreview.ocx' ActiveX Control Buffer Overflow
Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Horde 3.1 - 'Passwd' Module Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PeaZIP 2.6.1 - Compressed Filename Command Injection
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Online Armor < 3.5.0.12 - 'OAmon.sys' Local Privilege Escalation
The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Pers
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.