Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
IceWarp Merak Mail Server 9.4.1 - 'cleanHTML()' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Git 1.6.3 - Parameter Processing Remote Denial of Service
git-daemon in git 1.4.4.5 through 1.6.3 allows remote attackers to cause a denial of service (infinite loop and CPU cons
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IceWarp Merak Mail Server 9.4.1 - 'item.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Almond Classifieds 5.6.2 - Blind SQL Injection
SQL injection vulnerability in the Almond Classifieds (com_aclassf) component 5.6.2 for Joomla! allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GlassFish Enterprise Server 2.1 - Admin Console /webService/webServicesGeneral.jsf URI Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GlassFish Enterprise Server 2.1 - Admin Console /sysnet/registration.jsf URI Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GlassFish Enterprise Server 2.1 - Admin Console /resourceNode/resources.jsf URI Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GlassFish Enterprise Server 2.1 - Admin Console /customMBeans/customMBeans.jsf URI Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Admin Console in Sun GlassFish Enterprise Server 2.1 allow re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IceWarp Merak Mail Server 9.4.1 Groupware Component - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TemaTres 1.0.3 - Authentication Bypass / SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in TemaTres 1.031, when magic_quotes_gpc is disabled, allow remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VerliAdmin 0.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in VerliAdmin 0.3.7 and 0.3.8 allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sorinara Streaming Audio Player 0.9 - '.m3u' Local Stack Overflow (PoC)
Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Woodstock 4.2 404 - Error Page Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in ThemeServlet.java in Sun Woodstock 4.2, as used in Sun GlassFish Enterprise
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EW-MusicPlayer 0.8 - '.m3u' Local Buffer Overflow (PoC)
Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (appl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Openfire 3.x - jabber:iq:auth 'passwd_change' Remote Password Change
The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authentic
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 10 / OpenSolaris - 'dtrace' Local Kernel Denial of Service (PoC)
Multiple unspecified vulnerabilities in the DTrace ioctl handlers in Sun Solaris 10, and OpenSolaris before snv_114, all
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bmxplay 0.4.4b - '.bmx' Local Buffer Overflow (PoC)
Buffer overflow in BrotherSoft BMXPlay 0.4.4b allows remote attackers to cause a denial of service (application crash) o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Winn ASP Guestbook 1.01b - Remote Database Disclosure
Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader 8.1.2 < 9.0 - 'getIcon()' Memory Corruption
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x (Sparc64) - '/proc/iomem' Local Denial of Service
The pci_register_iommu_region function in arch/sparc/kernel/pci_common.c in the Linux kernel before 2.6.29 on the sparc6
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GUPnP 0.12.7 - Message Handling Denial of Service
GUPnP 0.12.7 allows remote attackers to cause a denial of service (crash) via an empty (1) subscription or (2) control m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MiniTwitter 0.2b - Multiple SQL Injections
Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenti
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Beatport Player 1.0.0.283 - '.m3u' Local Buffer Overflow (PoC)
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Beatport Player 1.0.0.283 - '.m3u' Local Overwrite (SEH)
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Beatport Player 1.0.0.283 - '.m3u' Local Stack Overflow (2)
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Beatport Player 1.0.0.283 - '.m3u' Local Stack Overflow (3)
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RM Downloader - '.smi' Universal Local Buffer Overflow
Stack-based buffer overflow in Mini-stream RM Downloader allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Addonics NAS Adapter FTP - Remote Denial of Service
Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mercury Audio Player 1.21 - '.m3u' Local Stack Overflow
Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MiniTwitter 0.2b - Remote User Options Changer
index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.