Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
PHPGKit 0.9 - 'connexion.php' Remote File Inclusion
PHP remote file inclusion vulnerability in connexion.php in PHPGKit 0.9 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SLmail Pro 6.3.1.0 - Multiple Remote Denial of Service / Memory Corruption Vulnerabilities
WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of se
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jack (tR) Jax LinkLists 1.00 - 'jax_linklists.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in jax_linklists.php in Jack (tR) Jax LinkLists 1.00 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
@lex Guestbook 4.0.5 - 'index.php?test' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
@lex Guestbook 4.0.5 - 'setup.php?language_setup' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in @lex Guestbook 4.0.5 and earlier allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office XP SP3 - '.PPT' File Buffer Overflow (MS08-016)
Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 f
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office XP SP3 - '.PPT' File Buffer Overflow (MS08-016)
Unspecified vulnerability in Microsoft Office Excel Viewer 2003 up to SP3 allows user-assisted remote attackers to execu
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
2X ThinClientServer 5.0 sp1-r3497 TFTP Service - Directory Traversal
Directory traversal vulnerability in 2X TFTP service (TFTPd.exe) 3.2.0.0 and earlier in 2X ThinClientServer 5.0_sp1-r349
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark 0.99.8 - SCCP Dissector Decode As Feature Denial of Service
The "decode as" feature in packet-bssap.c in the SCCP dissector in Wireshark (formerly Ethereal) 0.99.6 through 0.99.8 a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.4 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Simple Machines Forum (SMF) 1.1.4 allow remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark 0.99.8 - X.509sat Dissector Denial of Service
Multiple unspecified vulnerabilities in Wireshark (formerly Ethereal) 0.99.5 through 0.99.8 allow remote attackers to ca
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.4 - Empty Binary String Literal Remote Denial of Service
MySQL 5.0 before 5.0.66, 5.1 before 5.1.26, and 6.0 before 6.0.6 does not properly handle a b'' (b single-quote single-q
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark 0.99.8 - LDAP Dissector Denial of Service
The LDAP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.8 allows remote attackers to cause a denial of s
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DigiDomain 2.2 - 'suggest_result.asp' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Digiappz DigiDomain 2.2 allow remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DigiDomain 2.2 - 'lookup_result.asp?domain' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Digiappz DigiDomain 2.2 allow remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BSD (Multiple Distributions) - 'strfmon()' Integer Overflow
Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BlackBoard Academic Suite 6/7 - '/webapps/BlackBoard/execute/viewCatalog?searchText' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GeeCarts - 'view.php?id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Invision Power Board 2.x - 'Signature' iFrame Security
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.3.1 and earlier allows remote attackers to inject arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GeeCarts - 'show.php?id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GeeCarts - 'search.php?id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GeeCarts allow remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PECL 3.0.x - Alternative PHP Cache Extension 'apc_search_paths()' Remote Buffer Overflow
Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPAddressBook 2.0 - 'index.php' SQL Injection
Multiple SQL injection vulnerabilities in index.php in CoronaMatrix phpAddressBook 2.0 allow remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BlackBoard Academic Suite 6/7 - '/bin/common/announcement.pl?data__announcements___pk1_pk2__subject' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Academic Suite 7.x and earlier, and possibly some 8.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JAF CMS 4.0 RC2 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bomba Haber 2.0 - 'haberoku.php' SQL Injection
SQL injection vulnerability in haberoku.php in Serbay Arslanhan Bomba Haber 2.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell eDirectory 8.x - eMBox Utility 'edirutil' Command
The SOAP interface to the eMBox module in Novell eDirectory 8.7.3.9 and earlier, and 8.8.x before 8.8.2, relies on clien
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LeadTools MultiMedia 15 - 'LTMM15.dll' ActiveX Control Arbitrary File Overwrite
The (1) ltmmCaptureCtrl Class, (2) ltmmConvertCtrl Class, and (3) ltmmPlayCtrl Class ActiveX controls (ltmm15.dll 15.1.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB PJIRC Module 0.5 - 'irc.php' Local File Inclusion
Directory traversal vulnerability in forum/irc/irc.php in the PJIRC 0.5 module for phpBB allows remote attackers to incl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Quick Classifieds 1.0 - 'controlpannel/createHomepage.php3?DOCUMENT_ROOT' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ComScripts TEAM Quick Classifieds 1.0 via the DOCUMENT_ROOT parame
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.