Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Pligg CMS 9.9.0 - Remote Code Execution
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MJGUEST 6.8 - 'Guestbook.js.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
Multiple SQL injection vulnerabilities in submit.php in Pligg CMS 9.9.5 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unreal Tournament 2004 - Null Pointer Remote Denial of Service
Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dere
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PozScripts Classified Ads Script - 'cid' SQL Injection
SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Eyeball MessengerSDK 'CoVideoWindow.ocx' 5.0.907 - ActiveX Control Remote Buffer Overflow
Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 12.3(18) (FTP Server) - Remote (Attached to GDB)
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
e107 Plugin BLOG Engine 2.2 - Blind SQL Injection
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web Wiz Forum 9.5 - 'admin_category_details.asp?mode' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Owl Intranet Engine 0.95 - 'register.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgeb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web Wiz Forum 9.5 - 'admin_group_details.asp?mode' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Web Wiz Forum 9.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jamroom 3.3.8 - Cookie Authentication Bypass
The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authent
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of serv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZContents - 'minicalendar.php' Remote File Inclusion
PHP remote file inclusion vulnerability in modules/calendar/minicalendar.php in ezContents CMS allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of serv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AtomPhotoBlog 1.15 - 'atomPhotoBlog.php' SQL Injection
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Access - 'Snapview.ocx 10.0.5529.0' ActiveX Remote File Download
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snaps
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BIND 9.4.1 < 9.4.2 - Remote DNS Cache Poisoning (Metasploit)
The p_exec_query function in src/dns_query.c in pdnsd before 1.2.7-par allows remote attackers to cause a denial of serv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EMC Centera Universal Access 4.0_4735.p4 - 'Username' SQL Injection
SQL injection vulnerability in the CUA Login Module in EMC Centera Universal Access (CUA) 4.0_4735.p4 allows remote atta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.8 - '/tracking/courseLog.php?view' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.8 - 'user/user.php' Query String Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pre Survey Generator - 'default.asp' SQL Injection
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.8 - '/tracking/toolaccess_details.php?toolId' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.8 - 'learnPath/calendar/myagenda.php' Query String Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.8.10 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
SQL injection vulnerability in info.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EasyBookMarker 4.0 - 'ajaxp_backend.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in ajaxp_backend.php in MyioSoft EasyBookMarker 4.0 trial edition (tr) allows r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RunCMS 1.6.1 - 'bbPath[root_theme]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RunCMS 1.6.1 - 'bbPath[path]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Newbb Plus (newbb_plus) module 0.93 in RunCMS 1.6.1 allow remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EasyE-Cards 3.10 - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in staticpages/easyecards/index.php in MyioSoft EasyE-Cards 3.5 trial edition (tr) and 3.10a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XOOPS 2.0.18 - '/modules/system/admin.php?fct' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in modules/system/admin.php in XOOPS 2.0.18.1 allows remote attackers to inject
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.