Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari 4 - 'feeds:' URI Null Pointer Dereference Remote Denial of Service
Apple Safari 4 Beta build 528.16 allows remote attackers to cause a denial of service (NULL pointer dereference and appl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - Cloned Process 'CLONE_PARENT' Local Origin Validation
The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent pr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wesnoth 1.x - PythonAI Remote Code Execution
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute ar
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pPIM 1.0 - Multiple Vulnerabilities
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Magento 1.2 - 'downloader/index.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player 9/10 - Invalid Object Reference Remote Code Execution
Adobe Flash Player 9.x before 9.0.159.0 and 10.x before 10.0.22.87 does not properly remove references to destroyed obje
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Magento 1.2 - '/app/code/core/Mage/Admin/Model/Session.php?login['Username']' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Magento 1.2 - '/app/code/core/Mage/Adminhtml/controllers/IndexController.php?email' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! / Mambo Component gigCalendar 1.0 - 'banddetails.php' SQL Injection
Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_q
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows XP SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'sock.c' SO_BSDCOMPAT Option Information Disclosure
The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain struct
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TPTEST 3.1.7 - Stack Buffer Overflow (PoC)
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'make_indexed_dir()' Local Denial of Service
The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Enomaly ECP / Enomalism < 2.2.1 - Multiple Local Vulnerabilities
Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows lo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - XPath Expression Remote Denial of Service
sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vlinks 1.1.6 - 'id' SQL Injection
SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ideacart 0.02 - Local File Inclusion / SQL Injection
SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CmsFaethon 2.2.0 - 'item' SQL Injection
SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ea-gBook 0.1 - Remote Command Execution / Remote File Inclusion
PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ideacart 0.02 - Local File Inclusion / SQL Injection
Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary file
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Poppler 0.10.3 - Denial of Service
The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Poppler 0.10.3 - Denial of Service
The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GeoVision Digital Video Surveillance System 8.2 - Arbitrary File Disclosure
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote atta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bloggeruniverse 2.0 Beta - 'id' SQL Injection
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.