Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB
Valid tiny-erp 1.6 - SQL Injection
Multiple SQL injection vulnerabilities in Valid tiny-erp 1.6 and earlier allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB
Support Incident Tracker 3.65 - 'translate.php' Remote Code Execution
Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows rem
23RIESGO
abrir ↗Exploit-DB
Blogs manager 1.101 - SQL Injection
Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - console.lua pre-loading (Metasploit)
Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain pr
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin jetpack - 'sharedaddy.php' ID SQL Injection
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jetty Web Server - Directory Traversal
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Viscom Image Viewer CP Pro 8.0/Gold 6.0 - ActiveX Control (Metasploit)
Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageView
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Flexible Custom Post Type - 'id' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in edit-post.php in the Flexible Custom Post Type plugin before 0.1.7 for WordP
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Viscom Image Viewer CP Pro 8.0/Gold 6.0 - ActiveX Control (Metasploit)
Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Bui
23RIESGO
abrir ↗Exploit-DB
SonicWALL Aventail SSL-VPN - SQL Injection
SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB
Attachmate Reflection FTP Client - Heap Overflow
Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeWebShop 2.2.9 R2 - 'ajax_save_name.php' Remote Code Execution
Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeW
23RIESGO
abrir ↗Exploit-DB
Authenex A-Key/ASAS Web Management Control 3.1.0.2 - Blind SQL Injection
SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authenticati
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QuiXplorer 2.3 - Bugtraq Arbitrary File Upload
Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
optima apiftp server 1.5.2.13 - Multiple Vulnerabilities
APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (infinite l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
optima apiftp server 1.5.2.13 - Multiple Vulnerabilities
APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (NULL point
23RIESGO
abrir ↗Exploit-DB
Pixie CMS 1.01 < 1.04 - Blind SQL Injections
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin AdRotate 3.6.6 - SQL Injection
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mini-stream RM-MP3 Converter 3.1.2.1 - '.pls' Local Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code vi
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Support Incident Tracker 3.65 - Remote Command Execution (Metasploit)
ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive in
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Support Incident Tracker 3.65 - Remote Command Execution (Metasploit)
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Search Plugin for Hotaru CMS 1.4.2 - 'admin_index.php?site_name' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Hotaru.php in the Search plugin 1.3 for Hotaru CMS allow remote a
23RIESGO
abrir ↗Exploit-DB
Mambo 4.x - 'Zorder' SQL Injection
SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AbsoluteFTP 1.9.6 < 2.2.10 - 'LIST' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute ar
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenPAM - 'pam_start()' Local Privilege Escalation
Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to loa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
labwiki 1.1 - Multiple Vulnerabilities
edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated user
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
osCSS2 - '_ID' Local file Inclusion
Directory traversal vulnerability in catalog/content.php in osCSS2 2.1.0 and earlier allows remote attackers to read arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
labwiki 1.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrar
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.