Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8773Nuclei 4340Metasploit 3485✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
Just William's Amazon Webstore - 'Closeup.php?Image' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in JustWilliam's Amazon Webstore 04050100 allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP OpenView Radia Management Portal 1.0/2.0 - Remote Command Execution
Unknown vulnerability in Radia Management Agent (RMA) in HP OpenView Radia Management Portal (RMP) 1.x and 2.x allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Application Server 9i Webcache - Arbitrary File Corruption
The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoText 1.01 - Local User Informations Disclosure
StumbleInside GoText 1.01 stores sensitive username, mail address,and phone number information in plaintext in the GoTex
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FilePocket 1.2 - Local Proxy Password Disclosure
ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpCOIN 1.2 - 'login.php?PHPcoinsessid' SQL Injection
Multiple SQL injection vulnerabilities in phpCoin 1.2.2 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BakBone NetVault 7.1 - Local Privilege Escalation
nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows loc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dream4 Koobi CMS 4.2.3 - 'index.php?Q' SQL Injection
SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline E-Learning 1.5/1.6 - 'userInfo.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.5/1.6 - 'myagenda.php?coursePath' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dok
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.5/1.6 - 'toolaccess_details.php?tool' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dok
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dream4 Koobi CMS 4.2.3 - 'index.php?P' SQL Injection
SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline 1.5/1.6 - 'user_access_details.php?data' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dok
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Claroline E-Learning 1.5/1.6 - 'exercises_details.php?exo_id' SQL Injection
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPCart - Input Validation
phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ethereal 0.10.10 / tcpdump 3.9.1 - 'rsvp_print' Infinite Loop Denial of Service
The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BEA WebLogic Server 8.1 / WebLogic Express Administration Console - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web scrip
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tcpdump 3.8.x - 'ldp_print' Infinite Loop Denial of Service
tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP pac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GrayCMS 1.1 - 'error.php' Remote File Inclusion
PHP remote file inclusion vulnerability in error.php in GrayCMS 1.1 allows remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Convert-UUlib 1.04/1.05 Perl Module - Remote Buffer Overflow
Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a m
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tcpdump 3.8.x/3.9.1 - 'isis_print' Infinite Loop Denial of Service
The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a den
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetFTPd 4.2.2 - User Authentication Remote Buffer Overflow
Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long US
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPMyVisites 1.3 - 'Set_Lang' File Inclusion
set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tcpdump 3.8.x - 'rt_routing_info' Infinite Loop Denial of Service
tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP pac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yager 5.24 - Remote Buffer Overflow
Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted n
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
E-Cart 1.1 - 'index.cgi' Remote Command Execution
index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
StorePortal 2.63 - 'default.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OneWorldStore - IDOrder Information Disclosure
owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parame
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MailEnable Enterprise & Professional - https Remote Buffer Overflow
Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote at
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ImageMagick 6.x - '.PNM' Image Decoding Remote Buffer Overflow
Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attacke
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.