Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Openfire Server 3.6.0a - Admin Console Authentication Bypass (Metasploit)
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sielco Sistemi Winlog 2.07.16 - Multiple Vulnerabilities
Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 al
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sielco Sistemi Winlog 2.07.16 - Multiple Vulnerabilities
Stack-based buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA befor
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sielco Sistemi Winlog 2.07.16 - Multiple Vulnerabilities
TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
symantec Web gateway 5.0.2.8 - Multiple Vulnerabilities
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sielco Sistemi Winlog 2.07.16 - Multiple Vulnerabilities
TCPIPS_Story.dll in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sielco Sistemi Winlog 2.07.16 - Multiple Vulnerabilities
Array index error in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 might allow rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sielco Sistemi Winlog 2.07.16 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA bef
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec pcAnywhere 12.5.0 - 'Login' / 'Password' Remote Buffer Overflow
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
symantec Web gateway 5.0.2.8 - Multiple Vulnerabilities
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SugarCRM CE 6.3.1 - 'Unserialize()' PHP Code Execution (Metasploit)
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome 19.0.1084.52 - 'metro_driver.dll' DLL Loading Arbitrary Code Execution
Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain priv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kingview Touchview 6.53 - Multiple Heap Overflow Vulnerabilities
Heap-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted p
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Able2Extract and Able2Extract Server 6.0 - Memory Corruption
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a de
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Slimpdf Reader 1.0 - Memory Corruption
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a de
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Slimpdf Reader 1.0 - Memory Corruption
Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a deni
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iTunes 10 - Extended M3U Stack Buffer Overflow (Metasploit)
Heap-based buffer overflow in Apple iTunes before 10.6.3 allows remote attackers to execute arbitrary code or cause a de
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Able2Doc and Able2Doc Professional 6.0 - Memory Corruption
Unspecified vulnerability in Investintech.com Able2Extract and Able2Extract Server allows remote attackers to cause a de
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Able2Extract and Able2Extract Server 6.0 - Memory Corruption
Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a deni
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Slimpdf Reader 1.0 - Memory Corruption
Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Able2Extract and Able2Extract Server 6.0 - Memory Corruption
Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Able2Doc and Able2Doc Professional 6.0 - Memory Corruption
Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Able2Doc and Able2Doc Professional 6.0 - Memory Corruption
Unspecified vulnerability in Investintech.com Able2Doc and Able2Doc Professional allows remote attackers to cause a deni
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FCKEditor Core - 'Editor 'spellchecker.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the print_textinputs_var function in editor/dialog/fck_spellerpages/spellerp
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - Object Type Confusion (Metasploit)
Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Parodia 6.8 - 'employer-profile.asp' SQL Injection
SQL injection vulnerability in Parodia before 6.809 allows remote attackers to execute arbitrary SQL commands via unspec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kingview Touchview 6.53 - EIP Overwrite
Stack-based buffer overflow in WellinTech KingView 6.53 allows remote attackers to execute arbitrary code via a crafted
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XnView 1.98.8 - '.tiff' Image Processing Heap Overflow (1)
Multiple heap-based buffer overflows in XnView before 1.99 allow remote attackers to cause a denial of service (applicat
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XnView 1.98.8 - '.gif' Image Processing Heap Overflow
Heap-based buffer overflow in XnView before 1.99 allows remote attackers to cause a denial of service (application crash
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lattice Diamond Programmer 1.4.2 - Buffer Overflow (PoC)
Buffer overflow in programmer.exe in Lattice Diamond Programmer 1.4.2 allows user-assisted remote attackers to cause a d
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.