Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB✓ VexDay Proof
Joomla! Component JE Auto 1.0 - SQL Injection
SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox/Thunderbird/SeaMonkey - Multiple HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x b
23RIESGO
abrir ↗Exploit-DB
VMware Tools - Update OS Command Injection
The VMware Tools update functionality in VMware Workstation 6.5.x before 6.5.5 build 328052 and 7.x before 7.1.2 build 3
23RIESGO
abrir ↗Exploit-DB
WonderWare InBatch 9.0sp1 - Buffer Overflow
Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Processing Embed 0.5 - 'pluginurl' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Safe Search - 'v1' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - CSS Parser Denial of Service
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation
The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is con
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs va
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aigaion 1.3.4 - 'ID' SQL Injection
SQL injection vulnerability in indexlight.php in Aigaion 1.3.4 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zimplit CMS - 'English_manual_version_2.php?client' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zimplit CMS - 'zimplit.php?File' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.37 (RedHat / Ubuntu 10.04) - 'Full-Nelson.c' Local Privilege Escalation
The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU glibc - 'regcomp()' Stack Exhaustion Denial of Service
Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3,
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin - Client-Side Code Injection / Redirect Link Falsification
error.php in PhpMyAdmin 3.3.8.1, and other versions before 3.4.0-beta1, allows remote attackers to conduct cross-site sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ecommercemax Solutions Digital Goods Seller - SQL Injection
SQL injection vulnerability in shoppingcart.asp in Ecommercemax Solutions Digital-goods seller (DGS) 1.5 allows remote a
23RIESGO
abrir ↗Exploit-DB
Pulse CMS Basic - Local File Inclusion
Directory traversal vulnerability in includes/controller.php in Pulse CMS Basic before 1.2.9 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HotWebScripts HotWeb Rentals - 'resorts.asp' SQL Injection
SQL injection vulnerability in resorts.asp in HotWebScripts HotWeb Rentals allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Gatesoft Docusafe 4.1.0 - SQL Injection
SQL injection vulnerability in ECO.asp in GateSoft DocuSafe 4.1.0 and 4.1.2 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
UnrealIRCd 3.2.8.1 - Backdoor Command Execution (Metasploit)
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - LDSS Dissector Buffer Overflow
Heap-based buffer overflow in the dissect_ldss_transfer function (epan/dissectors/packet-ldss.c) in the LDSS dissector i
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
T-Dreams Cars Ads Package 2.0 - SQL Injection
SQL injection vulnerability in processview.asp in Techno Dreams (T-Dreams) Cars Ads Package 2.0 allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
T-Dreams Job Seekers Package 3.0 - SQL Injection
SQL injection vulnerability in Resumes/TD_RESUME_Indlist.asp in Techno Dreams (T-Dreams) Job Career Package 3.0 allows r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Viscom Image Viewer CP Gold 6 - ActiveX 'TifMergeMultiFiles()' Remote Buffer Overflow
Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageView
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DotNetNuke 5.5.1 - 'InstallWizard.aspx' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ananda Real Estate 3.4 - 'list.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ananda Real Estate 3.4 - 'list.asp' Multiple SQL Injections
SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier all
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.3.2 rc3 < 1.3.3b (FreeBSD) - Telnet IAC Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - (Authenticated) User Code Execution (Metasploit)
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Exploit-DB
Viscom Image Viewer CP Gold 5.5 - 'Image2PDF()' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx)
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.