Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB
Microsoft IIS 7.0 FTP Server - Stack Exhaustion Denial of Service (MS09-053) (Metasploit)
Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allo
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2010 - '.RTF' Header Stack Overflow
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader X 10.0.0 < 10.0.1 - Atom Type Confusion
Adobe Flash Player before 10.2.154.27 on Windows, Mac OS X, Linux, and Solaris and 10.2.156.12 and earlier on Android; A
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector 6.11 - Remote Buffer Overflow (DEP Bypass)
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component mDigg 2.2.8 - SQL Injection
SQL injection vulnerability in the mDigg (com_mdigg) component 2.2.8 for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP - 'OmniInet.exe' Opcode 27 Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector 6.20 - EXEC_CMD Buffer Overflow
Buffer overflow in omniinet.exe in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allows remot
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector 6.20 - Multiple Vulnerabilities
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Visio - 'VISIODWG.dll .DXF' File Handling (MS10-028) (Metasploit)
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to ex
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AzeoTech DaqFactory - Denial of Service
AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ManageEngine Support Center Plus 7.8 Build 7801 - Directory Traversal
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lotus Notes 8.0.x < 8.5.2 FP2 - Autonomy Keyview ('.lzh' Attachment) (Metasploit)
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ManageEngine Support Center Plus 7.8 Build 7801 - Directory Traversal
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remo
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ManageEngine ServiceDesk Plus 8.0 - Directory Traversal
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ManageEngine ServiceDesk Plus 8.0 - Directory Traversal
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 allows remo
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Black Ice Cover Page - ActiveX Control Arbitrary File Download (Metasploit)
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to for
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sielco Sistemi Winlog - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DreamBox DM800 - Arbitrary File Download
Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'nsTreeRange' Dangling Pointer (2)
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange da
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Black Ice Cover Page SDK - Insecure Method 'DownloadImageFileURL()' (Metasploit)
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to for
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Unified Operations Manager 8.5 - iptm/eventmon Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Unified Operations Manager 8.5 - 'iptm/advancedfind.do?extn' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Unified Operations Manager 8.5 - '/iptm/logicalTopo.do' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Unified Operations Manager 8.5 - '/iptm/faultmon/ui/dojo/Main/eventmon_wrapper.jsp' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Unified Operations Manager 8.5 - 'iptm/ddv.do?deviceInstanceName' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MSHTML!CObjectElement Use-After-Free (MS11-050) (Metasploit)
Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sunway ForceControl 6.1 - Multiple Heap Buffer Overflow Vulnerabilities
Heap-based buffer overflow in httpsvr.exe 6.0.5.3 in Sunway ForceControl 6.1 SP1, SP2, and SP3 allows remote attackers t
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark 1.4.5 - 'bytes_repr_len()' Null Pointer Dereference Denial of Service
The bytes_repr_len function in Wireshark 1.4.5 uses an incorrect pointer argument, which allows remote attackers to caus
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Websphere Application Server 7.0.0.13 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the Integrated Solutions Console (aka administrative conso
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft HyperV - Persistent Denial of Service (MS11-047)
Hyper-V in Microsoft Windows Server 2008 Gold, SP2, R2, and R2 SP1 allows guest OS users to cause a denial of service (h
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.