Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8410Nuclei 4231Metasploit 3467✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB✓ VexDay Proof
Oracle MySQL (Windows) - MOF Execution (Metasploit)
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ektron 8.02 - XSLT Transform Remote Code Execution (Metasploit)
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
(SSH.com Communications) SSH Tectia - USERAUTH Change Request Password Reset (Metasploit)
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advantech Studio 7.0 - SCADA/HMI Directory Traversal
Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and
23RIESGO
abrir ↗Exploit-DB
Symantec Messaging Gateway 9.5.3-3 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Symantec Messaging Gateway (SMG) before 10.0 allows remote attackers
23RIESGO
abrir ↗Exploit-DB
Symantec Messaging Gateway 9.5.3-3 - Arbitrary File Download
Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow r
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera Web Browser 12.11 - Crash (PoC)
Opera before 12.12 does not properly allocate memory for GIF images, which allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL (Linux) - Database Privilege Escalation
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗Exploit-DB
IBM System Director Agent - Remote System Level
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL - Remote User Enumeration
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other ver
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
(SSH.com Communications) SSH Tectia (SSH < 2.0-6.1.9.95 / Tectia 6.1.9.95) - Remote Authentication Bypass
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 5.1/5.5 (Windows) - 'MySQLJackpot' Remote Command Execution
Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other ver
28RIESGO
abrir ↗Exploit-DB
MySQL - Denial of Service (PoC)
Oracle MySQL 5.1.67 and earlier and 5.5.29 and earlier, and MariaDB 5.5.28a and possibly other versions, allows remote a
28RIESGO
abrir ↗Exploit-DB
MySQL (Linux) - Heap Overrun (PoC)
Heap-based buffer overflow in Oracle MySQL 5.5.19 and other versions through 5.5.28, and MariaDB 5.5.28a and possibly ot
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
freeSSHd 2.1.3 - Remote Authentication Bypass
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
freeFTPd 1.2.6 - Remote Authentication Bypass
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RIESGO
abrir ↗Exploit-DB
MySQL (Linux) - Stack Buffer Overrun (PoC)
Stack-based buffer overflow in the acl_get function in Oracle MySQL 5.5.19 and other versions through 5.5.28, and 5.1.53
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Elastix - 'page' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Video Lead Form - 'errMsg' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Video Lead Form plugin for WordPress allows remote attackers to inject a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7.7.2 - MIME Type Buffer Overflow (Metasploit)
Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mcrypt 2.6.8 - Stack Buffer Overflow (PoC)
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Forescout CounterACT - 'a' Open Redirection
Open redirect vulnerability in assets/login on the Forescout CounterACT NAC device before 7.0 allows remote attackers to
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mcrypt 2.5.8 - Local Stack Overflow
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7.7.2 - TeXML Style Element font-table Field Stack Buffer Overflow (Metasploit)
Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a de
50RIESGO
abrir ↗Exploit-DB
TrouSerS - Denial of Service
tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_of
28RIESGO
abrir ↗Exploit-DB
lighttpd 1.4.31 - Denial of Service (PoC)
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial o
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetIQ Privileged User Manager 2.3.1 - 'ldapagnt_eval()' Perl Remote Code Execution (Metasploit)
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manage
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
dotProject 2.1.x - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
dotProject 2.1.x - 'index.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in dotProject before 2.1.7 allow remote authenticated administrators to execute a
23RIESGO
abrir ↗Exploit-DB
Apple QuickTime 7.7.2 - Targa image Buffer Overflow
Buffer overflow in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause a denial of s
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.