Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
E-Smart Cart 1.0 - 'login.asp' SQL Injection
Multiple SQL injection vulnerabilities in embadmin/login.asp in E-SMARTCART 1.0 allow remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AkkyWareHOUSE '7-zip32.dll' 4.42 - Heap Buffer Overflow
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.x - '/inc/lib/language.lib.php?language' Traversal Local File Inclusion
Directory traversal vulnerability in inc/lib/language.lib.php in Claroline before 1.8.6 allows remote attackers to inclu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
STPHPLibrary - 'STPHPLIB_DIR' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime < 7.2 - SMIL Remote Integer Overflow
Integer overflow in Apple Quicktime before 7.2 on Mac OS X 10.3.9 and 10.4.9 allows user-assisted remote attackers to ex
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.x - '/admin/campusProblem.php?view' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.x - '/admin/advancedUserSearch.php?action' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Telecom Italy Alice Messenger - Remote Registry Key Manipulation
The HPRevolutionRegistryManager ActiveX control in Hp.Revolution.RegistryManager.dll 1 in Telecom Italy Alice Messenger
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.x - '/admin/adminusers.php?dir' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.8.6 allow remote authenticated administrators
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger - 'YVerInfo.dll 2007.8.27.1' ActiveX Buffer Overflow
Buffer overflow in a certain ActiveX control in YVerInfo.dll before 2007.8.27.1 in the Yahoo! services suite for Yahoo!
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microworld eScan (Multiple Products) - Local Privilege Escalation
MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Ev
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Norman Virus Control - 'nvcoaft51.sys' ioctl BF672028
The nvcoaft51 driver in Norman Virus Control (NVC) 5.82 uses weak permissions (unrestricted write access) for the NvcOa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Absolute Poll Manager XE 4.1 - 'xlaapmview.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in xlaapmview.asp in Absolute Poll Manager XE 4.1 allows remote attackers to in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 8.1.0.413 - 'webcam' Remote Crash
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denia
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EnterpriseDB Advanced Server 8.2 - Uninitialized Pointer
EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' Denial of Service (MS07-046)
Integer overflow in the AttemptWrite function in Graphics Rendering Engine (GDI) on Microsoft Windows 2000 SP4, XP SP2,
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Doomsday Engine 1.8.6/1.9 - Multiple Remote Vulnerabilities
Multiple buffer overflows in Doomsday (aka deng) 1.9.0-beta5.1 and earlier allow remote attackers to execute arbitrary c
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 8.1 - File Transfer Denial of Service
Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service (application crash) via ce
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco CallManager 4.2 / CUCM 4.2 - Logon Page 'lang' SQL Injection
Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft MSN Messenger 7.x/8.0? - Video Remote Heap Overflow
Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted rem
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft MSN Messenger 8.0 - Video Conversation Buffer Overflow
Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted rem
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ACG News 1.0 - 'index.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in ACG News 1.0 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Blizzard Entertainment StarCraft Brood War 1.15.1 - Minimap Preview Remote Denial of Service
Blizzard Entertainment StarCraft Brood War 1.15.1 and earlier allows remote attackers to cause a denial of service (appl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Thomson SpeedTouch ST 2030 (SIP Phone) - SIP Invite Message Remote Denial of Service
The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Arcadem 2.01 - SQL Injection / Remote File Inclusion
SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Motorola Timbuktu Pro 8.6.3.1367 - Directory Traversal
Directory traversal vulnerability in Motorola Timbuktu Pro before 8.6.5 for Windows allows remote attackers to create or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ISC BIND 8 - Remote Cache Poisoning (2)
The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS q
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Arcadem 2.01 - SQL Injection / Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Thomson SpeedTouch ST 2030 (SIP Phone) - Remote Denial of Service
The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ISC BIND 8 - Remote Cache Poisoning (1)
The (1) NSID_SHUFFLE_ONLY and (2) NSID_USE_POOL PRNG algorithms in ISC BIND 8 before 8.4.7-P1 generate predictable DNS q
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.