Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB✓ VexDay Proof
Microsoft Excel - Remote Buffer Overflow
Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allow re
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Security Agent Management Console - 'st_upload' Remote Code Execution
The Management Console (webagent.exe) in Cisco Security Agent 5.1, 5.2, and 6.0 before 6.0.2.145 allows remote attackers
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Host Integration Server 2004-2010 - Remote Denial of Service
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VeryTools VideoSpirit Pro 1.70 - '.visprj' Local Buffer Overflow (Metasploit)
Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions;
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MIT Kerberos 5 - kadmind Change Password Feature Remote Code Execution
The process_chpw_request function in schpw.c in the password-changing functionality in kadmind in MIT Kerberos 5 (aka kr
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VeryTools VideoSpirit Pro 1.70 - '.visprj' Local Buffer Overflow (Metasploit)
Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly othe
50RIESGO
abrir ↗Exploit-DB
tmux 1.3/1.4 - '-S' Option Incorrect SetGID Privilege Escalation
tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a f
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'inotify_init1()' Double-Free Local Denial of Service
Double free vulnerability in the inotify subsystem in the Linux kernel before 2.6.39 allows local users to cause a denia
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 1.1.8 - ModPlug ReadS3M Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ReadS3M method in load_s3m.cpp in libmodplug before 0.8.8.2 allows remote attackers t
50RIESGO
abrir ↗Exploit-DB
eyeos 2.3 - Multiple Vulnerabilities
Directory traversal vulnerability in framework/source/resource/qx/test/part/delay.php in QooxDoo 1.3 and possibly other
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Redmine 1.0.1/1.1.1 - 'projects/hg-hellowword/news/' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in app/views/layouts/base.rhtml in Redmine 1.0.1 through 1.1.1 allows remote at
23RIESGO
abrir ↗Exploit-DB
eyeos 2.3 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in framework/source/resource/qx/test/jsonp_primitive.php in QooxDoo 1.3 and pos
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
python-feedparser 5.0 - '/feedparser/feedparser.py' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser)
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Custom Pages 0.5.0.1 - Local File Inclusion
Directory traversal vulnerability in wp-download.php in the WP Custom Pages module 0.5.0.1 for WordPress allows remote a
43RIESGO
abrir ↗Exploit-DB
OpenEMR 4.0.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in setup.php in OpenEMR 4 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Exploit-DB
Yaws-Wiki 1.88-1 (Erlang) - Persistent / Reflective Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to injec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino iCalendar - MAILTO Buffer Overflow (Metasploit)
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server i
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Anzeigenmarkt 2011 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in Anzeigenmarkt 2011 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IPComp - encapsulation Kernel Memory Corruption
Multiple stack consumption vulnerabilities in the kernel in NetBSD 4.0, 5.0 before 5.0.3, and 5.1 before 5.1.1, when IPs
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
InTerra Blog Machine 1.84 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AWCM 2.x - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in AR Web Content Manager (AWCM) 2.1, 2.2, and possibly other ver
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
InTerra Blog Machine 1.84 - 'subject' HTML Injection
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions,
23RIESGO
abrir ↗Exploit-DB
PHPBoost 3.0 - Remote Download Backup
PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Perl 5.x - 'lc()' / 'uc()' TAINT Mode Protection Security Bypass
The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Andy's PHP KnowledgeBase 0.95.2 - 'viewusers.php' SQL Injection
Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ICJobSite 1.1 - 'pid' SQL Injection
SQL injection vulnerability in ICloudCenter ICJobSite 1.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tracks 1.7.2 - URI Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in app/controllers/todos_controller.rb in Tracks 1.7.2, 2.0RC2, and 2.0devel al
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Andy's PHP KnowledgeBase 0.95.4 - SQL Injection
SQL injection vulnerability in plugins/pdfClasses/pdfgen.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.4 allows remote a
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin BackWPup - Remote Code Execution / Local Code Execution
PHP remote file inclusion vulnerability in wp_xml_export.php in the BackWPup plugin before 1.7.2 for WordPress allows re
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 1.1.4 - 'AMV' Dangling Pointer (Metasploit)
libdirectx_plugin.dll in VideoLAN VLC Media Player before 1.1.8 allows remote attackers to execute arbitrary code via a
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.