Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB✓ VexDay Proof
pfSense - 'status_graph.php?if' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Vodpod Video Gallery 3.1.5 - 'vodpod_gallery_thumbs.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery P
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Cookex Agency CKForms - Local File Inclusion
Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote a
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pfSense - 'interfaces.php?if' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component ProDesk 1.5 - Local File Inclusion
Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Groupwise 8.0 - Multiple Remote Vulnerabilities
Multiple directory traversal vulnerabilities in the (1) WebAccess Agent and (2) Document Viewer Agent components in Nove
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASPilot Pilot Cart 7.3 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd IAC 1.3.x - Remote Command Execution
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.3.x - 'mb_strcut()' Information Disclosure
The mb_strcut function in Libmbfl 1.1.0, as used in PHP 5.3.x through 5.3.3, allows context-dependent attackers to obtai
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASPilot Pilot Cart 7.3 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in ASPilot Pilot Cart 7.3 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASPilot Pilot Cart 7.3 - Multiple Vulnerabilities
SQL injection vulnerability in pilot.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component ccInvoices - SQL Injection
SQL injection vulnerability in the ccInvoices (com_ccinvoices) component for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗Exploit-DB
Google Android 2.0 < 2.1 - Code Execution (Reverse Shell 10.0.2.2:2222/TCP)
WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not p
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pfSense 2 Beta 4 - 'graph.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in graph.php in pfSense 1.2.3 and 2 beta 4 allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MOXA MediaDBPlayback - ActiveX Control Buffer Overflow (Metasploit)
Stack-based buffer overflow in a certain ActiveX control in MediaDBPlayback.DLL 2.2.0.5 in the Moxa ActiveX SDK allows r
50RIESGO
abrir ↗Exploit-DB
PHP 5.3.3/5.2.14 - ZipArchive::getArchiveComment Null Pointer Dereference
The ZipArchive::getArchiveComment function in PHP 5.2.x through 5.2.14 and 5.3.x through 5.3.3 allows context-dependent
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - ActionIf Integer Denial of Service
Unspecified vulnerability in Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sami HTTP Server 2.0.1 - GET Denial of Service
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6/7/8 - Memory Corruption
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary cod
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SweetRice 0.6.7 - Multiple Vulnerabilities
The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the adminis
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Memory Corruption
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary cod
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve for Laptops & Desktops LGServer - Multiple Commands Buffer Overflows (Metasploit)
Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SweetRice 0.6.7 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Acrobat Reader 9.4 - Memory Corruption
The EScript.api plugin in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.1, and 8.x before 8.2.6 on Windows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Webster HTTP Server - GET Buffer Overflow (Metasploit)
Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve License Service - 'GCR NETWORK' Remote Buffer Overflow (Metasploit)
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execu
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve for Laptops & Desktops LGServer - Remote Buffer Overflow (Metasploit) (3)
Multiple stack-based buffer overflows in CA (Computer Associates) BrightStor ARCserve Backup for Laptops and Desktops r1
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Unified Communications Manager 8.0 - Invalid Argument Privilege Escalation
/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve for Laptops & Desktops LGServer - Remote Buffer Overflow (Metasploit) (2)
Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
digiSHOP 2.0.2 - SQL Injection
SQL injection vulnerability in cart.php in digiSHOP 2.0.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.