Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Softbiz Image Gallery - 'config.php?msg' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
8E6 Technologies R3000 - Host Header Internet Filter Security Bypass
8e6 R3000 Internet Filter 2.0.12.10 allows remote attackers to bypass intended restrictions via an extra HTTP Host heade
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Softbiz Image Gallery - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Crafty Syntax Live Help 2.14.6 - 'livehelp_js.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in livehelp_js.php in Crafty Syntax Live Help (CSLH) 2.14.6 allows remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Softbiz Image Gallery - 'cleanup.php?msg' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Meeting Room Booking System (MRBS) 1.2.6 - 'help.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Keld PHP-MySQL News Script 0.7.1 - 'login.php' SQL Injection
SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XAMPP Linux 1.6 - 'iart.php?text' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Meeting Room Booking System (MRBS) 1.2.6 - 'month.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Meeting Room Booking System (MRBS) 1.2.6 - 'day.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pcshey Portal - 'kategori.asp' SQL Injection
SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
UNAK-CMS 1.5 - 'connector.php' Local File Inclusion
Absolute path traversal vulnerability in fckeditor/editor/filemanager/browser/default/connectors/php/connector.php in UN
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Meeting Room Booking System (MRBS) 1.2.6 - 'report.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Meeting Room Booking System (MRBS) 1.2.6 - 'search.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XAMPP Linux 1.6 - 'ming.php?text' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Homes 4 Sale - 'results.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in result.php in Chris Bunting Homes 4 Sale allows remote attackers to inject a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Meeting Room Booking System (MRBS) 1.2.6 - 'week.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pligg CMS 9.9.5 - 'CAPTCHA' Registration Automation Security Bypass
The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random n
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
e-vision CMS 2.02 - SQL Injection / Arbitrary File Upload / Information Gathering
Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
e-vision CMS 2.02 - SQL Injection / Arbitrary File Upload / Information Gathering
Multiple SQL injection vulnerabilities in e-Vision CMS 2.02 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
freeForum 1.7 - 'acuparam' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke Book Catalog Module 1.0 - 'catid' SQL Injection
SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IrfanView 3.99 - '.IFF' File Local Stack Buffer Overflow
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a craf
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 6.0.16 - 'HttpServletResponse.sendError()' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 6.0.16 - 'RequestDispatcher' Information Disclosure
Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, pe
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'net/ipv6/ip6_output.c' Null Pointer Dereference Denial of Service
The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle cer
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
libxslt 1.1.x - RC4 Encryption and Decryption functions Buffer Overflow
Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.x - CoreGraphics Multiple Memory Corruption Vulnerabilities
Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitr
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
common Solutions csphonebook 1.02 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pligg CMS 9.9.0 - Remote Code Execution
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.