Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.429GitHub PoC 14.270VulnCheck XDB 8693Nuclei 4299Metasploit 3474✓ solo verificadosrecientespopularesriesgo
24.455 exploits
Exploit-DB✓ VexDay Proof
Application Enhancer (APE) 2.0.2 - Local Privilege Escalation
Unsanity Application Enhancer (APE) 2.0.2 installs with insecure permissions for the (1) ApplicationEnhancer binary and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 9.10 - '.jpg' Image DHT Marker Heap Corruption
Heap-based buffer overflow in Opera 9.02 allows remote attackers to execute arbitrary code via a JPEG file with an inval
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Berlios GPSD 2.7 - Remote Format String (Metasploit)
Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Packeteer PacketShaper 8.0 - Multiple Buffer Overflow (Denial of Service) (PoC) Vulnerabilities
Buffer overflow in Packeteer PacketShaper PacketWise 8.x allows remote authenticated users to cause a denial of service
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Access Manager 3 Identity Server - 'IssueInstant' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in nidp/idff/sso in Novell Access Manager Identity Server before 3.0.0-1013 all
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CreateAuction - 'Cats.asp' SQL Injection
SQL injection vulnerability in cats.asp in createauction allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 3.x < 4.0 - 'vga_ioctl()' Local Privilege Escalation
Unspecified vulnerability in sys/dev/pci/vga_pci.c in the VGA graphics driver for wscons in OpenBSD 3.9 and 4.0, when th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy Banner Pro 2.8 - 'info.php' Remote File Inclusion
PHP remote file inclusion vulnerability in info.php in Easy Banner Pro 2.8 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow (Metasploit)
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.0.5 - Trackback UTF-7 SQL Injection
WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multiple PDF Readers - Multiple Remote Buffer Overflows
The Adobe PDF specification 1.3, as implemented by Adobe Acrobat before 8.0.0, allows remote attackers to have an unknow
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Shopstorenow E-Commerce Shopping Cart - 'Orange.asp' SQL Injection
SQL injection vulnerability in orange.asp in ShopStoreNow E-commerce Shopping Cart allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'edittag.pl?file' Arbitrary File Disclosure
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - DiskManagement BOM 'cron' Local Privilege Escalation
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kolayindir Download - 'down.asp' SQL Injection
SQL injection vulnerability in down.asp in Kolayindir Download (Yenionline) allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'edittag.cgi?file' Arbitrary File Disclosure
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ig shop 1.0 - Code Execution / SQL Injection
Multiple SQL injection vulnerabilities in display_review.php in iGeneric iG Shop 1.4 and earlier allow remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Coppermine Photo Gallery 1.4.11 - SQL Injection
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated adminis
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'mkpw_mp.cgi?plain' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RI Blog 1.3 - 'search.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.asp in RI Blog 1.3 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Coppermine Photo Gallery 1.4.10 - 'xpl.php' SQL Injection
SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4.8 - DiskManagement BOM Privilege Escalation
DiskManagementTool in the DiskManagement.framework 92.29 on Mac OS X 10.4.8 does not properly validate Bill of Materials
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'edittag_mp.cgi?file' Arbitrary File Disclosure
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'mkpw.pl?plain' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'mkpw.cgi?plain' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in EditTag 1.2 allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EditTag 1.2 - 'edittag_mp.pl?file' Arbitrary File Disclosure
Multiple absolute path traversal vulnerabilities in EditTag 1.2 allow remote attackers to read arbitrary files via an ab
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader Plugin 7.0.x - 'acroreader' Cross-Site Scripting
Double free vulnerability in the Adobe Acrobat Reader Plugin before 8.0.0, as used in Mozilla Firefox 1.5.0.7, allows re
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Backup Exec System Recovery Manager 7.0 - FileUpload Class Unauthorized File Upload
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime (Windows 2000) - 'rtsp URL Handler' Remote Buffer Overflow
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 7.1.3 - 'HREFTrack' Cross-Zone Scripting
Cross-zone scripting vulnerability in Apple Quicktime 3 to 7.1.3 allows remote user-assisted attackers to execute arbitr
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.