Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.978exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.248VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
TWiki 4.2.2 - 'action' Remote Code Execution
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eXtrovert software Thyme 1.3 - 'add_calendars.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in add_calendars.php in eXtrovert Software Thyme 1.3 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BlueCUBE CMS - 'tienda.php' SQL Injection
SQL injection vulnerability in tienda.php in BlueCUBE CMS allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DESlock+ < 3.2.7 - Local Kernel Overflow (PoC)
Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kerne
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multiple Vendor FTP Server - Long Command Handling Security
ftpd in OpenBSD 4.3, FreeBSD 7.0, NetBSD 4.0, Solaris, and possibly other operating systems interprets long commands fro
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DESlock+ < 3.2.7 - Local Kernel Race Condition Denial of Service (PoC)
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Achievo 1.3.2 - 'atknodetype' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in dispatch.php in Achievo 1.3.2 allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HyperStop WebHost Directory 1.2 - Database Disclosure
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Pro Bid 5.2.4/6.04 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in PHP Pro Bid (PPB) 6.04 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cars & Vehicle - 'page.php' SQL Injection
SQL injection vulnerability in page.php in Cars & Vehicle (aka Cars-Vehicle Script) allows remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Quick Cart 3.1 - 'admin.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin.php in Quick.Cart 3.1 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Solaris 9/10 Text Editors - Command Execution
Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors relate
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Femitter FTP Server 1.03 - 'RETR' Remote Denial of Service (PoC)
The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Quick CMS Lite 2.1 - 'admin.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin.php in OpenSolution Quick.Cms.Lite 2.1 allows remote attackers to inje
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Postfix < 2.4.9/2.5.5/2.6-20080902 - '.forward' Local Denial of Service
20RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unreal Engine - 'UnChan.cpp' Failed Assertion Remote Denial of Service
The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Accellion File Transfer Appliance Error Report Message - Open Email Relay
courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and po
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CzarNews 1.20 - Account Hijacking SQL Injection
SQL injection vulnerability in cn_users.php in CzarNews 1.20 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 3.2 - 'server_databases.php' Remote Command Execution
libraries/database_interface.lib.php in phpMyAdmin before 2.11.9.1 allows remote authenticated users to execute arbitrar
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unreal Engine 3 - Failed Memory Allocation Remote Denial of Service
Unreal engine 3, as used in Unreal Tournament 3 1.3, Frontlines: Fuel of War 1.1.1, and other products, allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dynamic MP3 Lister 2.0.1 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Dynamic MP3 Lister 2.0.1 allow remote attackers to i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Paranews 3.4 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in news.php in s0nic Paranews 3.4 allow remote attackers to inject a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Avant Browser 11.7 Build 9 - JavaScript Engine Integer Overflow
Integer overflow in the JavaScript engine in Avant Browser 11.7 Build 9 and earlier allows remote attackers to cause a d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS 1.1.4/2.0 / iPod 1.1.4/2.0 touch Safari WebKit - 'alert()' Remote Denial of Service
Off-by-one error in the _web_drawInRect:withFont:ellipsis:alignment:measureOnly function in WebKit in Safari in Apple iP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZoneAlarm Security Suite 7.0 - AntiVirus Directory Path Buffer Overflow (PoC)
Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nooms 1.1 - 'search.php?q' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in NooMS 1.1 allow remote attackers to inject arbitrary web script o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yourownbux 4.0 - 'cookie' Authentication Bypass
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Autodealers CMS AutOnline - 'pageid' SQL Injection
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy Photo Gallery 2.1 - Cross-Site Scripting / File Disclosure/Bypass / SQL Injection
SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to exe
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.