Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Grayscale Blog 0.8.0 - Security Bypass / SQL Injection / Cross-Site Scripting
Grayscale Blog 0.8.0, and possibly earlier versions, allows remote attackers to gain privileges via direct requests with
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - FTP Server Response Denial of Service (MS07-016)
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitr
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2.0 / PHP with PECL ZIP 1.8.3 - 'zip://' URL Wrapper Buffer Overflow
Stack-based buffer overflow in the zip:// URL wrapper in PECL ZIP 1.8.3 and earlier, as bundled with PHP 5.2.0 and 5.2.1
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JCCorp URLShrink Free 1.3.1 - 'CreateURL.php' Remote File Inclusion
PHP remote file inclusion vulnerability in createurl.php in JCcorp (aka James Coyle) URLshrink allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 3.x/4.x - ICMPv6 Packet Handling Remote Buffer Overflow
Buffer overflow in kern/uipc_mbuf2.c in OpenBSD 3.9 and 4.0 allows remote attackers to execute arbitrary code via fragme
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader Plugin 'AcroPDF.dll' 8.0.0.0 - Resource Consumption
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to caus
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 2.0.0.2 - Document.Cookie Path Argument Denial of Service
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FiSH-irssi - Multiple Remote Buffer Overflow Vulnerabilities
Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rediff Toolbar - ActiveX Control Remote Denial of Service
The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows remote attackers to cause a denial of service via uns
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mod_security 2.1.0 - ASCIIZ byte POST Rules Bypass
Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
radscan conquest 8.2 - Multiple Vulnerabilities
Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WinZip 10.0.7245 - FileView ActiveX Buffer Overflow (2)
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.01b - 'check' Buffer Overflow (PoC)
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Firebug 1.03 - Rep.JS Script Code Injection
Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug exte
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Silc Server 1.0.2 - New Channel Remote Denial of Service
The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Gnome Evolution 2.x - GnuPG Arbitrary Content Injection
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EPortfolio 1.0 - Client-Side Input Validation
Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.4.6 - 'mssql_[p]connect()' Local Buffer Overflow
Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GnuPG 1.x - Signed Message Arbitrary Content Injection
GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE Konqueror 3.5 - JavaScript IFrame Denial of Service
ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE Konqueror 3.5.7 - Assert Denial of Service
Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a denial of service (faile
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KMail 1.x - GnuPG Arbitrary Content Injection
Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Asterisk 1.2.15/1.4.0 - Remote Denial of Service
Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5 - 'wddx_deserialize()' String Append Crash
The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RRDBrowse 1.6 - Arbitrary File Disclosure
Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP < 4.4.5/5.2.1 - WDDX Session Deserialization Information Leak
The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize th
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.4.3 < 4.4.6 - 'PHPinfo()' Cross-Site Scripting
A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zend Platform 2.2.1 - 'PHP.INI' File Modification
ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.1.1 - Arbitrary Command Execution
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externa
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.1.1 - '/wp-includes/theme.php?iz' Arbitrary Command Execution
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externa
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.