Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
woltlab burning board 3.0.x - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
nForum 1.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpCommunity 2.1.8 - SQL Injection / Directory Traversal / Cross-Site Scripting
Multiple directory traversal vulnerabilities in phpCommunity 2 2.1.8 allow remote attackers to read arbitrary files via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHORTAIL 1.2.1 - 'poster.php' Multiple HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPRecipeBook 2.24 - 'base_id' SQL Injection
SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Fusion Mod Book Panel - 'bookid' SQL Injection
SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TinXCMS 3.5 - 'rss.php' SQL Injection
SQL injection vulnerability in system/rss.php in TinX/cms 3.x before 3.5.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy File Sharing Web Server 4.8 - File Disclosure
Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
cURL/libcURL 7.19.3 - HTTP 'Location:' Redirect Security Bypass
The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 2.0.x - Nested 'window.print()' Denial of Service
Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sopcast SopCore Control - 'sopocx.ocx' Command Execution
Insecure method vulnerability in the SopCast SopCore ActiveX control in sopocx.ocx 3.0.3.501 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Blogsa 1.0 - 'Widgets.aspx' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Widgets.aspx in Blogsa 1.0 Beta 3 and earlier allows remote attackers to inj
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZ-Blog beta1 - Delete All Posts / SQL Injection
Multiple SQL injection vulnerabilities in EZ-Blog Beta 1, when magic_quotes_gpc is disabled, allow remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HTC Touch - vCard over IP Denial of Service
HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consum
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NovaStor NovaNET 12 - 'DtbClsLogin()' Remote Stack Buffer Overflow
Stack-based buffer overflow in the DtbClsLogin function in NovaStor NovaNET 12 allows remote attackers to (1) execute ar
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZ-Blog beta1 - Delete All Posts / SQL Injection
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'seccomp' System Call Security Bypass
The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell eDirectory iMonitor - 'Accept-Language' Request Buffer Overflow (PoC)
Off-by-one error in the iMonitor component in Novell eDirectory 8.8 SP3, 8.8 SP3 FTF3, and possibly other versions allow
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Graugon PHP Article Publisher 1.0 - SQL Injection / Cookie Handling
Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Merak Media Player 3.2 - '.m3u' File Local Buffer Overflow (SEH)
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long strin
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Graugon PHP Article Publisher 1.0 - SQL Injection / Cookie Handling
admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrativ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Document Library 1.0.1 - Arbitrary Change Admin
admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Media Commands - '.m3u' Local Overwrite (SEH)
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Irokez Blog 0.7.3.2 - Multiple Input Validation Vulnerabilities
Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, al
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Orbit Downloader 2.8.4 - 'Hostname' Remote Buffer Overflow
Stack-based buffer overflow in Orbit Downloader 2.8.2 and 2.8.3, and possibly other versions before 2.8.5, allows remote
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
djbdns 1.05 - Long Response Packet Remote Cache Poisoning
The response_addname function in response.c in Daniel J. Bernstein djbdns 1.05 and earlier does not constrain offsets in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Websphere Application Server 6.1/7.0 - Administrative Console Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 bef
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSC 0.11.x - PKCS#11 Implementation Unauthorized Access
OpenSC before 0.11.7 allows physically proximate attackers to bypass intended PIN requirements and read private data obj
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.