Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.175GitHub PoC 14.096VulnCheck XDB 8607Nuclei 4255Metasploit 3474✓ solo verificadosrecientespopularesriesgo
24.446 exploits
Exploit-DB✓ VexDay Proof
Joomla! Component com_gcalendar 1.1.2 - 'gcid' SQL Injection
SQL injection vulnerability in the Google Calendar GCalendar (com_gcalendar) component 1.1.2, 2.1.4, and possibly earlie
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Radio istek scripti 2.5 - Remote Configuration Disclosure
RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Serenity Audio Player Playlist - '.m3u' Local Buffer Overflow
Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote atta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpBazar-2.1.1fix - Remote Administration-Panel
phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP-Cumulus 1.20 - Full Path Disclosure / Cross-Site Scripting
WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive informat
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.8.0 - Remote Denial of Service
XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (crash) by uploading or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.10 - APPE DELE Denial of Service
TYPSoft FTP Server 1.10 allows remote authenticated users to cause a denial of service (crash) by sending an APPE (appen
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pointcomma 3.8b2 - Remote File Inclusion
PHP remote file inclusion vulnerability in includes/classes/pctemplate.php in PointComma 3.8b2 and earlier allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
outreach project tool 1.2.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
kr-web 1.1b2 - Remote File Inclusion
PHP remote file inclusion vulnerability in adm/krgourl.php in KR-Web 1.1b2 and earlier allows remote attackers to execut
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XM Easy Personal FTP Server 5.8.0 - Remote Denial of Service
Dxmsoft XM Easy Personal FTP Server 5.8.0 allows remote authenticated users to cause a denial of service (daemon outage)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
klinza Professional CMS 5.0.1 - 'menulast.php' Local File Inclusion
Directory traversal vulnerability in funzioni/lib/menulast.php in klinza professional cms 5.0.1 and earlier allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Quick.Cart 3.4 / Quick.CMS 2.4 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authen
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NukeHall 0.3 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in NukeHall 0.3 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phptraverse 0.8.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in assets/plugins/mp3_id/mp3_id.php in PHP Traverser 0.8.0 allows remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Quick.Cart 3.4 / Quick.CMS 2.4 - Delete Function Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Quick.Cart 3.4 allow remote attackers to hijack the authen
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Python < 2.5.2 Imageop Module - 'imageop.crop()' Buffer Overflow
Multiple integer overflows in imageop.c in the imageop module in Python 1.5.2 through 2.5.1 allow context-dependent atta
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Autodesk SoftImage 7.0 Scene - '.TOC' File Remote Code Execution
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - 'GeomFromWKB()' Function First Argument Geometry Value Handling Denial of Service
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Autodesk Maya Script - Nodes Arbitrary Command Execution
Autodesk Maya 8.0, 8.5, 2008, 2009, and 2010 and Alias Wavefront Maya 6.5 and 7.0 allow remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - SELECT Statement WHERE Clause Sub-query Denial of Service
mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of cert
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Autodesk SoftImage Scene TOC - Arbitrary Command Execution
Autodesk Softimage 7.x and Softimage XSI 6.x allow remote attackers to execute arbitrary JavaScript code via a scene pac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco VPN Client - Integer Overflow Denial of Service
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Betsy CMS versions 3.5 - Local File Inclusion
Directory traversal vulnerability in admin/popup.php in Betsy CMS 3.5 allows remote attackers to include and execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cacti 0.8.x - 'graph.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Com_Joomclip - 'cat' SQL Injection
SQL injection vulnerability in the JoomClip (com_joomclip) component for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TEKUVA - Password Reminder Authentication Bypass
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AIMP2 Audio Converter 2.53 build 330 - Playlist '.pls' Unicode Buffer Overflow
Stack-based buffer overflow in AIMP2 Audio Converter 2.53 (build 330) and earlier allows remote attackers to cause a den
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE 4.3.3 - KDELibs 'dtoa()' Remote Code Execution
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera Web Browser 10.01 - 'dtoa()' Remote Code Execution
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.