Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB
vam shop 1.6 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in VaM Shop 1.6, 1.6.1, and probably earlier versions llow remote at
23RIESGO
abrir ↗Exploit-DB
DriveCrypt 5.3 - Local Kernel Ring0 SYSTEM
DCR.sys driver in SecurStar DriveCrypt 5.4, 5.3, and earlier allows local users to execute arbitrary code via a crafted
23RIESGO
abrir ↗Exploit-DB
Linux Kernel (Solaris 10 / < 5.10 138888-01) - Local Privilege Escalation
tun in IP Tunnel in Solaris 10 and OpenSolaris snv_01 through snv_76 allows local users to cause a denial of service (pa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TinyBB 1.2 - SQL Injection
SQL injection vulnerability in inc/tinybb-settings.php in tinyBB 1.2, when magic_quotes_gpc is disabled, allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JBoss JMX - Console Beanshell Deployer WAR Upload and Deployment (Metasploit)
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Common Control Library 'Comctl32' Heap Overflow (MS10-081)
Heap-based buffer overflow in Comctl32.dll (aka the common control library) in Microsoft Windows XP SP2 and SP3, Windows
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lotus CMS Fraise 3.0 - Local File Inclusion / Remote Code Execution
Directory traversal vulnerability in core/lib/router.php in LotusCMS Fraise 3.0, when magic_quotes_gpc is disabled, allo
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.3.2 rc3 < 1.3.3b (Linux) - Telnet IAC Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.2 < 1.3.0 (Linux) - 'sreplace' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the sreplace function in ProFTPD 1.3.0 and earlier allows remote attackers, probably auth
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KingView 6.5.3 - SCADA HMI Heap Overflow
Heap-based buffer overflow in HistorySvr.exe in WellinTech KingView 6.53 allows remote attackers to execute arbitrary co
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX - mDNSResponder UPnP Location Overflow (Metasploit)
Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of servic
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fonality trixbox CE 2.6.1 - 'langChoice' Local File Inclusion (Metasploit)
Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VeryTools VideoSpirit Pro 1.68 - Local Buffer Overflow
Buffer overflow in VideoSpirit Pro 1.6.8.1 and possibly earlier versions, and VideoSpirit Lite 1.4.0.1 and possibly othe
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java - Runtime New Plugin docbase Buffer Overflow (Metasploit)
Unspecified vulnerability in the New Java Plug-in component in Oracle Java SE and Java for Business 6 Update 21 allows r
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector Manager 6.11 - RDS Service Remote Denial of Service
The RDS service (rds.exe) in HP Data Protector Manager 6.11 allows remote attackers to cause a denial of service (crash)
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
axdcms-0.1.1 - Local File Inclusion
Directory traversal vulnerability in modules/profile/user.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VeryTools VideoSpirit Pro 1.68 - Local Buffer Overflow
Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions;
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Signed Applet Social Engineering - Code Execution (Metasploit)
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetSupport Manager Agent - Remote Buffer Overflow (1)
Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows
50RIESGO
abrir ↗Exploit-DB
Zwii 2.1.1 - Remote File Inclusion
Directory traversal vulnerability in system/system.php in Zwii 2.1.1, when magic_quotes_gpc is disabled and register_glo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7.6.6 - Invalid SMIL URI Buffer Overflow (Metasploit)
Stack-based buffer overflow in the error-logging functionality in Apple QuickTime before 7.6.7 on Windows allows remote
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS/PWS - CGI Filename Double Decode Command Execution (MS01-026) (Metasploit)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7.6.7 - _Marshaled_pUnk Code Execution (Metasploit)
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions all
50RIESGO
abrir ↗Exploit-DB
GNU libc/regcomp(3) - Multiple Vulnerabilities
Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3,
35RIESGO
abrir ↗Exploit-DB
GNU libc/regcomp(3) - Multiple Vulnerabilities
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows c
35RIESGO
abrir ↗Exploit-DB
Phenotype CMS 3.0 - SQL Injection
SQL injection vulnerability in the store function in _phenotype/system/class/PhenoTypeDataObject.class.php in Phenotype
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! 1.0.x - 'ordering' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the com_search module for Joomla! 1.0.x through 1.0.15 allows remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PhpGedView 4.2.3 - Local File Inclusion
Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Music Animation Machine MIDI Player - Local Buffer Overflow (SEH)
Stack-based buffer overflow in Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions all
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.3.2 - 'zend_strtod()' Floating-Point Value Denial of Service
strtod.c, as used in the zend_strtod function in PHP 5.2 before 5.2.17 and 5.3 before 5.3.5, and other products, allows
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.