Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Active Web Mail 4 - Authentication Bypass
Multiple SQL injection vulnerabilities in login.aspx in Active Price Comparison 4.0 allow remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RakhiSoftware Shopping Cart - PHPSESSID Cookie Manipulation Full Path Disclosure
RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote attackers to obtain sensitive information via an
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RakhiSoftware Shopping Cart - 'product.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in product.php in RakhiSoftware Price Comparison Script (aka Shoppin
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Turnkey Arcade Script - SQL Injection (1)
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web Calendar System 3.12/3.30 - Multiple Vulnerabilities
SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the us
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linksys WRT160N - 'apply.cgi' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AssoCIateD 1.4.4 - 'menu' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in AssoCIateD (aka ACID) 1.2.0 and earlier allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Goople CMS 1.7 - Arbitrary Code Execution
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
W3C Amaya 10.1 Web Browser - URL Bar Remote Stack Overflow (PoC)
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code v
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
W3C Amaya 10.1 Web Browser - 'id' Remote Stack Overflow (PoC)
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code v
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Goople CMS 1.7 - Insecure Cookie Handling
Static code injection vulnerability in gooplecms/admin/account/action/editpass.php in Goople CMS 1.7 allows remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft XML Core Services DTD - Cross-Domain Scripting (MS08-069)
Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office,
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pilot Group PG Roommate Finder Solution - SQL Injection
SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft XML Core Services DTD - Cross-Domain Scripting (MS08-069)
Cross-domain vulnerability in Microsoft XML Core Services 3.0 and 4.0, as used in Internet Explorer, allows remote attac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Softbiz Classifieds Script - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in signinform.php in Softbiz Classifieds Script allows remote attackers to inje
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GeSHi 1.0.x - XML Parsing Remote Denial of Service
The highlighting functionality in geshi.php in GeSHi before 1.0.8 allows remote attackers to cause a denial of service (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2.6 - 'error_log' Safe_mode Bypass
The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AskPert - Authentication Bypass
SQL injection vulnerability in index.php in W3matter RevSense 1.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Vista - 'iphlpapi.dll' Local Kernel Buffer Overflow
Stack-based buffer overflow in Microsoft Device IO Control in iphlpapi.dll in Microsoft Windows Vista Gold and SP1 allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RevSense 1.0 - Authentication Bypass
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MusicBox 2.3.8 - 'viewalbums.php' SQL Injection
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SaturnCMS - Blind SQL Injection
SQL injection vulnerability in lib/url/meta_url.php in SaturnCMS allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (1)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BoutikOne CMS - 'search_query' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in BoutikOne CMS allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Customer 1.2 - Authentication Bypass
SQL injection vulnerability in login.php in Simple Customer as downloaded on 20081118 allows remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (1)
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 9.62 - 'file://' Local Heap Overflow
Multiple buffer overflows in Opera before 9.63 might allow (1) remote attackers to execute arbitrary code via a crafted
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VeryPDF PDFView - ActiveX Component Heap Buffer Overflow
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alstrasoft Web Host Directory 1.2 - Multiple Vulnerabilities
AlstraSoft Web Host Directory stores sensitive information under the web root with insufficient access control, which al
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.