Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.316exploits catalogados
34.835CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4239Metasploit 3468✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB✓ VexDay Proof
AwingSoft Winds3D Player 3.5 - SceneURL Download and Execute (Metasploit)
The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneU
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe - U3D CLODProgressiveMeshDeclaration Array Overrun (Metasploit) (1)
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might all
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Madwifi - SIOCGIWSCAN Buffer Overflow (Metasploit)
Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execut
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Data Binding Memory Corruption (MS08-078) (Metasploit)
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Messenger Server 2.0 - Accept-Language Overflow (Metasploit)
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute ar
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Computer Associates License Client - GETCONFIG Overflow (Metasploit)
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execu
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe - FlateDecode Stream Predictor 02 Integer Overflow (Metasploit) (1)
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
McAfee ePolicy Orchestrator / ProtectionPilot - Remote Overflow (Metasploit)
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attac
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - 'createTextRange()' Code Execution (MS06-013) (Metasploit)
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arb
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RhinoSoft Serv-U FTPd Server - MDTM Overflow (Metasploit)
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft WINS - Service Memory Overwrite (MS04-045) (Metasploit)
The WINS service (wins.exe) on Microsoft Windows NT Server 4.0, Windows 2000 Server, and Windows Server 2003 allows remo
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/Vista/2003 - Metafile Escape() SetAbortProc Code Execution (MS06-001) (Metasploit)
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbit
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TFTPD32 < 2.21 - 'Filename' Remote Buffer Overflow (Metasploit)
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filenam
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ISS - 'PAM.dll' ICQ Parser Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell iPrint Client Browser Plugin - 'call-back-url' Remote Stack Overflow
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BoutikOne 1.0 - SQL Injection
SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SmarterMail 7.1.3876 - Directory Traversal
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
SQL injection vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote atta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime FLI LinePacket - Remote Code Execution
Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attacker
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
xt:Commerce Gambio 2008 < 2010 - 'reviews.php' Error-Based SQL Injection
SQL injection vulnerability in product_reviews_info.php in xt:Commerce Gambio 2008 allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.6.4 - 'Plugin' EnsureCachedAttrParamArrays Remote Code Execution
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netautor Professional 5.5 - 'login2.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor P
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mojoportal - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.27 < 2.6.36 (RedHat x86-64) - 'compat' Local Privilege Escalation
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mojoportal - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - HFPicture Record Parsing Remote Code Execution
Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.6.36-rc4-git2 (x86-64) - 'ia32syscall' Emulation Privilege Escalation
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BACnet OPC Client - Local Buffer Overflow (1)
Stack-based buffer overflow in WTclient.dll in SCADA Engine BACnet OPC Client before 1.0.25 allows user-assisted remote
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multple I-Escorts Products - 'escorts_search.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in escorts_search.php in I-Escorts Directory Script and Agency Scrip
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.