Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.465Referência 23.022GitHub PoC 15.031VulnCheck XDB 8860Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
WordPress Plugin NewsLetter 1.5 - Remote File Disclosure
Directory traversal vulnerability in preview.php in the Plugin Newsletter plugin 1.5 for WordPress allows remote attacke
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lattice Semiconductor PAC-Designer 6.21 - '.PAC' Local Overflow
Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin FCChat Widget 2.2.x - 'upload.php' Arbitrary File Upload
Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Font Uploader 1.2.4 - Arbitrary File Upload
Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin MM Forms Community 2.2.6 - Arbitrary File Upload
Unrestricted file upload vulnerability in includes/doajaxfileupload.php in the MM Forms Community plugin 2.2.5 and 2.2.6
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Object File Handling Remote Code Execution (Metasploit)
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts 2.2.1.1 - Remote Command Execution (Metasploit)
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Log1 CMS - 'writeInfo()' PHP Code Injection (Metasploit)
Static code injection vulnerability in inc/function.base.php in Ajax File and Image Manager before 1.1, as used in tinym
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GIMP script-fu - Server Buffer Overflow (Metasploit)
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and p
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MPlayer - '.SAMI' Subtitle File Buffer Overflow (Metasploit)
Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, all
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Web Content Management System 1.1 < 1.3 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Simple Web Content Management System 1.1 allow remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.0.2.8 - Command Execution (Metasploit)
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5.0.2 - Local/Remote File Inclusion / Remote Code Execution
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
appRain CMF - Arbitrary '.PHP' File Upload (Metasploit)
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenOffice - OLE Importer DocumentSummaryInformation Stream Handling Overflow (Metasploit)
Heap-based buffer overflow in the OLE importer in OpenOffice.org before 2.4 allows remote attackers to cause a denial of
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - Misaligned Memory Denial of Service
Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 on the SPARC and Itanium platforms does not properly perform data a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - Multiple Dissector Denial of Service Vulnerabilities
Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allows remote attackers to cause a denial of service (infinite loop
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - DIAMETER Dissector Denial of Service
epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 does
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Mod_Auth_OpenID - Session Stealing
mod_auth_openid before 0.7 for Apache uses world-readable permissions for /tmp/mod_auth_openid.db, which allows local us
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - Multiple Dissector Denial of Service Vulnerabilities
Multiple integer overflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a den
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - Multiple Dissector Denial of Service Vulnerabilities
Multiple integer underflows in Wireshark 1.4.x before 1.4.13 and 1.6.x before 1.6.8 allow remote attackers to cause a de
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pragmaMx 1.12.1 - '/includes/wysiwyg/spaw/editor/plugins/imgpopup/img_popup.php?img_url' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pligg CMS 1.x - 'module.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Pligg CMS before 1.2.2 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pragmaMx 1.12.1 - 'modules.php' URI Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in pragmaMx 1.x before 1.12.2 allow remote attackers to inject arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Client 4.91 SP4 - Local Privilege Escalation
NICM.SYS driver 3.0.0.4, as used in Novell NetWare Client 4.91 SP4, allows local users to execute arbitrary code by open
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Plogger Photo Gallery - SQL Injection
SQL injection vulnerability in plog-rss.php in Plogger 1.0 Beta 3.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mosh - Remote Denial of Service
The terminal dispatcher in mosh before 1.2.1 allows remote authenticated users to cause a denial of service (long loop a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP StorageWorks P4000 - Virtual SAN Appliance Command Execution (Metasploit)
lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yandex.Server 2010 9.0 - 'text' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search/ in Yandex.Server 2010 9.0 Enterprise allows remote attackers to inje
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.