Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.266GitHub PoC 14.131VulnCheck XDB 8635Nuclei 4274Metasploit 3474✓ solo verificadosrecientespopularesriesgo
24.451 exploits
Exploit-DB✓ VexDay Proof
Magento 1.2 - 'downloader/index.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Magento 1.2.0 and 1.2.1.1 allow remote attackers to inject arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! / Mambo Component gigCalendar 1.0 - 'banddetails.php' SQL Injection
Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_q
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'sock.c' SO_BSDCOMPAT Option Information Disclosure
The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain struct
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows XP SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Enomaly ECP / Enomalism < 2.2.1 - Multiple Local Vulnerabilities
Argument injection vulnerability in Enomaly Elastic Computing Platform (ECP), formerly Enomalism, before 2.1.1 allows lo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'make_indexed_dir()' Local Denial of Service
The make_indexed_dir function in fs/ext4/namei.c in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TPTEST 3.1.7 - Stack Buffer Overflow (PoC)
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 allows remote attackers to have an unknown
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 6.0.9 - XPath Expression Remote Denial of Service
sql/item_xmlfunc.cc in MySQL 5.1 before 5.1.32 and 6.0 before 6.0.10 allows remote authenticated users to cause a denial
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vlinks 1.1.6 - 'id' SQL Injection
SQL injection vulnerability in page.php in Vlinks 1.0.3 and 1.1.6 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CmsFaethon 2.2.0 - 'item' SQL Injection
SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ea-gBook 0.1 - Remote Command Execution / Remote File Inclusion
PHP remote file inclusion vulnerability in index_inc.php in ea gBook 0.1 and 0.1.4 allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ideacart 0.02 - Local File Inclusion / SQL Injection
Directory traversal vulnerability in index.php in IdeaCart 0.02 and 0.02a allows remote attackers to read arbitrary file
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ideacart 0.02 - Local File Inclusion / SQL Injection
SQL injection vulnerability in secure/index.php in IdeaCart 0.02 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Poppler 0.10.3 - Denial of Service
The JBIG2Stream::readSymbolDictSeg function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Poppler 0.10.3 - Denial of Service
The FormWidgetChoice::loadDefaults function in Poppler before 0.10.4 allows remote attackers to cause a denial of servic
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bloggeruniverse 2.0 Beta - 'id' SQL Injection
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GeoVision Digital Video Surveillance System 8.2 - Arbitrary File Disclosure
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote atta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TYPO3 < 4.0.12/4.1.10/4.2.6 - 'jumpUrl' Remote File Disclosure
The jumpUrl mechanism in class.tslib_fe.php in TYPO3 3.3.x through 3.8.x, 4.0 before 4.0.12, 4.1 before 4.1.10, 4.2 befo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.3 - 'mod_sql' 'Username' SQL Injection
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL co
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Banking@Home 2.1 - 'login.asp' Multiple SQL Injections
SQL injection vulnerability in Login.asp in Craft Silicon Banking@Home 2.1 and earlier allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Swann DVR4 SecuraNet - Directory Traversal
Directory traversal vulnerability in the administrative web server in Swann DVR4-SecuraNet allows remote attackers to re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd - 'mod_mysql' Authentication Bypass
ProFTPD Server 1.3.1, with NLS support enabled, allows remote attackers to bypass SQL injection protection mechanisms vi
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FlexCMS 2.5 - 'catId' SQL Injection
SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId para
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WB News 2.1.1 - config[installdir] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in WB News 2.0.1, when register_globals is enabled, allow remote atta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FotoWeb 6.0 - 'Grid.fwx?search' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Gaeste 1.6 - 'gastbuch.php' Remote File Disclosure
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FotoWeb 6.0 - 'Login.fwx?s' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in FotoWeb 6.0 (Build 273) allow remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell QuickFinder Server - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterp
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.