Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.745exploits catalogados
38.712CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.884Exploit-DB 24.485GitHub PoC 16.068VulnCheck XDB 9333Nuclei 4457Metasploit 3518✓ solo verificadosrecientespopularesriesgo
82.745 exploits
Exploit-DB✓ VexDay Proof
JC URLShrink 1.3.1 - Remote Code Execution
JCcorp URLshrink 1.3.1 allows remote attackers to execute arbitrary PHP code via the email address field in an HTML link
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drake CMS 0.3.7 - '404.php' Local File Inclusion
Directory traversal vulnerability in 404.php in Drake CMS allows remote attackers to include and execute arbitrary local
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Remote Code
The RPC service in mediasvr.exe in CA BrightStor ARCserve Backup 11.5 SP2 build 4237 allows remote attackers to execute
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus Domino Server 6.5 - 'Username' Remote Denial of Service
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.20 with DCCP Support - Memory Disclosure (2)
The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify
23RIESGO
abrir ↗Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (HTTP)
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2.1 - 'Session.Save_Path()' TMPDIR open_basedir Restriction Bypass
PHP 4 before 4.4.5 and PHP 5 before 5.2.1, when using an empty session save path (session.save_path), uses the TMPDIR de
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.20 with DCCP Support - Memory Disclosure (2)
Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XOOPS module Articles 1.03 - 'index.php?cat_id' SQL Injection
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to ex
23RIESGO
abrir ↗Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP)
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RIESGO
abrir ↗Metasploit500
Windows ANI LoadAniIcon() Chunk Size Stack Buffer Overflow (SMTP)
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.20 with DCCP Support - Memory Disclosure (1)
Integer signedness error in the DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.4.5/4.4.6 - 'session_decode()' Double-Free (PoC)
Double free vulnerability in the unserializer in PHP 4.4.5 and 4.4.6 allows context-dependent attackers to execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.4.4 - 'Zip_Entry_Read()' Integer Overflow
Integer overflow in the zip_read_entry function in PHP 4 before 4.4.5 allows remote attackers to execute arbitrary code
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.20 with DCCP Support - Memory Disclosure (1)
The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mephisto Blog 0.7.3 - Search Function Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Mephisto 0.7.3 allows remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CcCounter 2.0 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in CcCounter 2.0 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy File Sharing FTP Server 2.0 (Windows 2000 SP4) - 'PASS' Remote Overflow
Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrar
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Recordset Double-Free Memory (MS07-009)
Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by creating
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fizzle 0.5 - RSS Feed HTML Injection
Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - IPv6_SockGlue.c Null Pointer Dereference Denial of Service
The do_ipv6_setsockopt function in net/ipv6/ipv6_sockglue.c in Linux kernel before 2.6.20, and possibly other versions,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP < 4.4.5/5.2.1 - '_SESSION' Deserialization Overwrite
PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WarFTP 1.65 - 'USER' Remote Buffer Overflow
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of s
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP < 4.4.5/5.2.1 - '_SESSION unset()' Local Overflow
The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session vari
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Frontbase 4.2.7 (Windows) - Remote Buffer Overflow
Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privil
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Asterisk 1.2.16/1.4.1 - SIP INVITE Remote Denial of Service
The channel driver in Asterisk before 1.2.17 and 1.4.x before 1.4.2 allows remote attackers to cause a denial of service
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free File Hosting System 1.1 - 'contact.php?AD_BODY_TEMP' Remote File Inclusion
PHP remote file inclusion vulnerability in contact.php in Free File Hosting 1.1 and earlier allows remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.0.1 - 'LOGIN' Remote IMAP Stack Buffer Overflow
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free File Hosting System 1.1 - 'register.php?AD_BODY_TEMP' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free File Hosting System 1.1 - 'login.php?AD_BODY_TEMP' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.