Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.043exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.260VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
okul siteleri 'com_mezun' Component - SQL Injection
SQL injection vulnerability in the com_mezun component for Joomla! allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.7 - 'tree.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated u
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Rapid Recipe 1.6.5 - SQL Injection
Multiple SQL injection vulnerabilities in index.php in the Rapid Recipe (com_rapidrecipe) 1.6.5 component for Joomla! al
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.7 - 'graph_view.php?filter' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.7 - 'graph.php?view_type' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.7 - 'graph_xport.php?local_graph_id' SQL Injection
Multiple SQL injection vulnerabilities in Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote authenticated u
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opium OPI Server and CyanPrintIP - Format String / Denial of Service
Format string vulnerability in the ReportSysLogEvent function in the LPD server in cyan soft Opium OPI Server 4.10.1028
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VWar 1.5 - 'calendar.php' SQL Injection
SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sentinel Protection Server 7.x/Keys Server 1.0.x - Backslash Directory Traversal
Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
cyan soft - Multiple Applications Format String / Denial of Service Vulnerabilities
The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Larson Network Print Server 9.4.2 build 105 - 'LstNPS' Logging Function USEP Command Remote Format String
Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Larson Network Print Server 9.4.2 build 105 (LstNPS) - 'NPSpcSVR.exe' License Command Remote Overflow
Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
F5 BIG-IP 9.4.3 - Web Management Interface Cross-Site Request Forgery
Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Group Logic ExtremeZ-IP File and Print Servers 5.1.2 x15 - Multiple Vulnerabilities
ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.23 < 2.6.24 - 'vmsplice' Local Privilege Escalation (1)
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer befo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 6.0.15 - Cookie Quote Handling Remote Information Disclosure
Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double q
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)
The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certai
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.23 < 2.6.24 - 'vmsplice' Local Privilege Escalation (1)
The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)
The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Managed Workplace Service Center 4.x/5.x/6.x - Installation Information Disclosure
Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitiv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
S9Y Serendipity Freetag-plugin 2.95 - 'style' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Expl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Calimero.CMS 3.3 - 'id' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS 3.3 allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joovili 2.1 - 'members_help.php' Remote File Inclusion
PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IEA Software (Multiple Products) - POST Denial of Service
The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other ve
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch Instant Messaging 2.0.8.1 - Multiple Vulnerabilities
Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereferen
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MODx 0.9.6 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Works 8.0 - File Converter Field Length Remote Code Execution
Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Wor
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch WS_FTP Server 6 - '/WSFTPSVR/FTPLogServer/LogViewer.asp' Authentication Bypass
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass aut
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat and Reader 8.1.1 - Multiple Arbitrary Code Execution / Security Vulnerabilities
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TinTin++ / WinTin++ 1.97.9 - '#chat' Multiple Vulnerabilities
Stack-based buffer overflow in the add_line_buffer function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attacke
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.