Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8150Nuclei 4193Metasploit 3462✓ solo verificadosrecientespopularesriesgo
3462 exploits
Metasploit600
Active Collab "chat module" Remote PHP Code Injection Exploit
functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute
43RIESGO
abrir ↗Metasploit600
PHP Volunteer Management System v1.0.2 Arbitrary File Upload Vulnerability
PHP Volunteer Management System 1.0.2 Arbitrary File Upload
36RIESGO
abrir ↗Metasploit600
WordPress Asset-Manager PHP File Upload Vulnerability
WordPress Plugin Asset-Manager <= 2.0 PHP File Upload
63RIESGO
abrir ↗Metasploit300
IBM Lotus QuickR qp2 ActiveX Buffer Overflow
Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-00
50RIESGO
abrir ↗Metasploit300
IBM Rational ClearQuest CQOle Remote Code Execution
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 bef
50RIESGO
abrir ↗Metasploit300
GIMP script-fu Server Buffer Overflow
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and p
60RIESGO
abrir ↗Metasploit600
Symantec Web Gateway 5.0.2.8 Arbitrary PHP File Upload Vulnerability
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to u
50RIESGO
abrir ↗Metasploit600
Symantec Web Gateway 5.0.2.8 relfile File Inclusion Vulnerability
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RIESGO
abrir ↗Metasploit600
Symantec Web Gateway 5.0.2.8 ipchange.php Command Injection
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RIESGO
abrir ↗Metasploit300
Lattice Semiconductor ispVM System XCF File Handling Overflow
Lattice Semiconductor ispVM System 18.0.2 XCF File Handling Buffer Overflow
36RIESGO
abrir ↗Metasploit300
Lattice Semiconductor PAC-Designer 6.21 Symbol Value Buffer Overflow
Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary
43RIESGO
abrir ↗Metasploit300
Apple QuickTime TeXML Style Element Stack Buffer Overflow
Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbit
43RIESGO
abrir ↗Metasploit300
SAP NetWeaver Dispatcher DiagTraceR3Info Buffer Overflow
The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispa
50RIESGO
abrir ↗Metasploit300
PHP apache_request_headers Function Buffer Overflow
Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote at
50RIESGO
abrir ↗Metasploit300
Adobe Flash Player Object Type Confusion
Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on
60RIESGO
abrir ↗Metasploit600
PHP CGI Argument Injection
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir ↗Metasploit600
McAfee Virtual Technician MVTControl 6.3.0.1911 GetObject Vulnerability
An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to ex
43RIESGO
abrir ↗Metasploit300
InduSoft Web Studio ISSymbol.ocx InternationalSeparator() Heap Overflow
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol v
50RIESGO
abrir ↗Metasploit600
WebCalendar 1.2.4 Pre-Auth Remote Code Injection
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RIESGO
abrir ↗Metasploit300
Samsung NET-i Viewer Multiple ActiveX BackupToAvi() Remote Overflow
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0
50RIESGO
abrir ↗Metasploit300
Oracle TNS Listener Checker
The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.
40RIESGO
abrir ↗Metasploit300
Oracle AutoVue ActiveX Control SetMarkupMode Buffer Overflow
Unspecified vulnerability in the Oracle AutoVue Office component in Oracle Supply Chain Products Suite 20.1.1 allows rem
50RIESGO
abrir ↗Metasploit200
MS12-027 MSCOMCTL ActiveX Buffer Overflow
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls
100RIESGO
abrir ↗Metasploit300
Samba SetInformationPolicy AuditEventsInfo Heap Overflow
The RPC code generator in Samba 3.x before 3.4.16, 3.5.x before 3.5.14, and 3.6.x before 3.6.4 does not implement valida
60RIESGO
abrir ↗Metasploit600
Distinct TFTP 3.10 Writable Directory Traversal Execution
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remo
68RIESGO
abrir ↗Metasploit600
Dolibarr ERP/CRM Post-Auth OS Command Injection
Dolibarr ERP/CRM Post-Auth OS Command Injection
63RIESGO
abrir ↗Metasploit300
BlazeVideo HDTV Player Pro v6.6 Filename Handling Vulnerability
BlazeVideo HDTV Player Pro 6.6.0.3 Filename Handling Buffer Overflow
36RIESGO
abrir ↗Metasploit300
IBM Cognos tm1admsd.exe Overflow
Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2
50RIESGO
abrir ↗Metasploit300
TRENDnet SecurView Internet Camera UltraMJCam OpenFileDlg Buffer Overflow
Stack-based buffer overflow in the UltraMJCam ActiveX Control in TRENDnet SecurView TV-IP121WN Wireless Internet Camera
60RIESGO
abrir ↗Metasploit200
Quest InTrust Annotation Objects Uninitialized Pointer
The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not prope
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.