Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Apple 2.0.4 - Safari Local Cross-Site Scripting
Unspecified vulnerability in Apple Safari allows local users to obtain sensitive information (saved keychain passwords)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx 3.8.5.0' Remote Stack Overflow
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Office Viewer OCX 3.2.0.5 - Multiple Denial of Service Vulnerabilities
Multiple buffer overflows in the Office Viewer OCX ActiveX control (oa.ocx) 3.2 allow remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Net Portal Dynamic System (NPDS) 5.10 - Remote Code Execution (2)
Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zoo 2.10 - .ZOO Compression Algorithm Remote Denial of Service
PicoZip allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pre News Manager 1.0 - SQL Injection
SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPSecurityAdmin 4.0.2 - 'Logout.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/logout.php in Justin Koivisto SecurityAdmin for PHP (aka PHPSecurityA
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Word Viewer OCX 3.2 - Remote Denial of Service
The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Exp
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Progress WebSpeed 3.0/3.1 - Denial of Service
WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ObieWebsite Mini Web Shop 2 - 'Sendmail.php?PATH_INFO' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3proxy 0.5.3g - exec-shield 'proxy.c logurl()' Remote Overflow
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CMS Made Simple 1.0.5 - 'Stylesheet.php' SQL Injection
SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ObieWebsite Mini Web Shop 2 - 'order_form.php?PATH_INFO' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Atomix MP3 - '.MP3' File Buffer Overflow
Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin wordTube 1.43 - 'wpPATH' Remote File Inclusion
Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when reg
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 2.0.0.3 - Href Denial of Service
Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
X.Org X Window System Xserver 1.3 - XRender Extension Divide by Zero Denial of Service
The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Gazi Download Portal - 'Down_Indir.asp' SQL Injection
SQL injection vulnerability in down_indir.asp in Gazi Download Portal allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aventail Connect 4.1.2.13 - Hostname Remote Buffer Overflow
Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (applicat
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3proxy 0.5.3g (Linux) - 'proxy.c logurl()' Remote Buffer Overflow
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
E-Annu - 'home.php' SQL Injection
SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a pa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3proxy 0.5.3g (Windows x86) - 'proxy.c logurl()' Remote Buffer Overflow
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fenice Oms server 1.10 - exec-shield Remote Buffer Overflow
Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - NCTAudioFile2.AudioFile ActiveX Remote Stack Overflow (2)
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple prod
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ManageEngine Password Manager Pro Build 5401 - Database Remote Unauthorized Access
ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injectin
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache AXIS 1.0 - Non-Existent WSDL Path Information Disclosure
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which re
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyDNS 1.1.0 - Remote Heap Overflow (PoC)
Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and poss
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IPIX Image Well - ActiveX 'iPIX-ImageWell-ipix.dll' Remote Buffer Overflow
Multiple buffer overflows in the Internet Pictures Corporation iPIX Image Well ActiveX control (iPIX-ImageWell-ipix.dll)
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invali
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MoinMoin 1.5.x - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in MoinMoin 1.5.7 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.