Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.429GitHub PoC 14.270VulnCheck XDB 8693Nuclei 4299Metasploit 3474✓ solo verificadosrecientespopularesriesgo
24.455 exploits
Exploit-DB✓ VexDay Proof
SSC DiskAccess NFS Client - 'DAPCNFSD.dll' Remote Stack Buffer Overflow
Buffer overflow in the EnumPrintersA function in dapcnfsd.dll 0.6.4.0 in Shaffer Solutions (SSC) DiskAccess NFS Client a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Multiple ActiveX Controls Denial of Service Vulnerabilities
Multiple ActiveX controls in Microsoft Windows 2000, XP, 2003, and Vista allows remote attackers to cause a denial of se
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve - 'msgeng.exe' Remote Heap Overflow (2)
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro VirusWall 3.81 - 'vscan/VSAPI' Local Buffer Overflow
Buffer overflow in libvsapi.so in the VSAPI library in Trend Micro VirusWall 3.81 for Linux, as used by IScan.BASE/vscan
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA BrightStor ARCserve - 'msgeng.exe' Remote Heap Overflow (1)
Multiple buffer overflows in LGSERVER.EXE in CA BrightStor ARCserve Backup for Laptops and Desktops r11.0 through r11.1
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MDPro 1.0.76 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in MAXdev MDPro 1.0.76 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SpoonLabs Vivvo Article Management CMS 3.40 - 'Show_Webfeed.php' SQL Injection
SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 al
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Telestream Flip4Mac - 'WMV' File Remote Memory Corruption
Telestream Flip4Mac Windows Media Components for Quicktime 2.1.0.33 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AdMentor - Admin Login SQL Injection
Multiple SQL injection vulnerabilities in the administrative login page (admin/login.asp) in ASPCode.net AdMentor allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Installer Package 2.1.5 - Filename Format String
Format string vulnerability in Apple Installer 2.1.5 on Mac OS X 10.4.8 allows user-assisted remote attackers to execute
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Metaframe Presentation Server Print Provider - Buffer Overflow (PoC)
Stack-based buffer overflow in the print provider library (cpprov.dll) in Citrix Presentation Server 4.0, MetaFrame Pres
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FD Script 1.3.2 - 'download.php' Remote File Disclosure
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FD Script 1.3.x - 'FName' Information Disclosure
download.php in FD Script 1.3.2 and earlier allows remote attackers to read source of files under the web document root
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Membership Manager 1.5 - 'admin.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin.php in Interactive-Scripts.Com PHP Membership Manager 1.5 allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 8.0 - Notification Message HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in the Contact Details functionality in Yahoo! Messenger 8.1.0.209 a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2 - FOpen 'Safe_mode' Restriction Bypass
The fopen function in PHP 5.2.0 does not properly handle invalid URI handlers, which allows context-dependent attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Excel - Malformed Palette Record Denial of Service (PoC) (MS07-002)
Heap-based buffer overflow in Microsoft Excel 2000 SP3, 2002 SP3, 2003 SP2, 2004 for Mac, and v.X for Mac allows user-as
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.x - Software Update Format String
Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aztek Forum 4.0 - Multiple Vulnerabilities
SQL injection vulnerability in forum/load.php in Aztek Forum 4.00 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Word 2000 - Malformed Function Code Execution
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GTK2 GDKPixBufLoader - Remote Denial of Service
The GdkPixbufLoader function in GIMP ToolKit (GTK+) in GTK 2 (gtk2) before 2.4.13 allows context-dependent attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 1.x/2.0.x - Pingback SourceURI Denial of Service / Information Disclosure
WordPress allows remote attackers to cause a denial of service (bandwidth or thread consumption) via pingback service ca
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 10g - SYS.KUPV$FT.ATTACH_JOB PL / SQL Injection
Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vote-Pro 4.0 - 'poll_frame.php?poll_id' Remote Code Execution
Multiple eval injection vulnerabilities in Vote! Pro 4.0, and possibly earlier, allow remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - QuickDraw GetSrcBits32ARGB Remote Memory Corruption
The _GetSrcBits32ARGB function in Apple QuickDraw, as used by Quicktime 7.1.3 and other applications on Mac OS X 10.4.8
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 10g - SYS.KUPW$WORKER.MAIN PL / SQL Injection
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - 'UserNotificationCenter' Local Privilege Escalation
The CFUserNotificationSendRequest function in UserNotificationCenter.app in Apple Mac OS X 10.4.8, when used in combinat
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3Com TFTP Service (3CTftpSvc) 2.0.1 - Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a d
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Upload Service 1.0 - 'top.php?maindir' Remote File Inclusion
PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.x Kernel - 'shared_region_map_file_np()' Memory Corruption
The shared_region_map_file_np function in Apple Mac OS X 10.4.8 and earlier kernel allows local users to cause a denial
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.