Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
82.745exploits catalogados
38.712CVEs con explotación pública
24.695probados en laboratorio
TodosReferência 24.884Exploit-DB 24.485GitHub PoC 16.068VulnCheck XDB 9333Nuclei 4457Metasploit 3518✓ solo verificadosrecientespopularesriesgo
82.745 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows Vista - Windows Mail Local File Execution
Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a lin
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
dproxy 0.5 - Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eWebquiz 8 - 'eWebQuiz.asp' SQL Injection
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2.1 - 'Unserialize()' Local Information Leak
PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a seriali
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ethernet Device Drivers Frame Padding - 'Etherleak' Infomation Leakage
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.0.x/2.2.x/2.4.x (FreeBSD 4.x) - Network Device Driver Frame Padding Information Disclosure
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MzK Blog - 'Katgoster.asp' SQL Injection
SQL injection vulnerability in katgoster.asp in MzK Blog (tr) allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Grandstream Budge Tone-200 IP Phone - Digest domain Denial of Service
The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Asterisk 1.4 SIP T.38 SDP - Parsing Remote Stack Buffer Overflow (PoC) (1)
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in As
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Asterisk 1.4 SIP T.38 SDP - Parsing Remote Stack Buffer Overflow (PoC) (2)
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in As
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla FireFox 1.5.x/2.0 - FTP PASV Port-Scanning
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to for
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mercur Messaging 2005 < SP4 - IMAP Remote (Egghunter)
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE Konqueror 3.x/IOSlave - FTP PASV Port-Scanning
The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 9.x - FTP PASV Port-Scanning
The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FTPDMIN 0.96 - 'LIST' Remote Denial of Service
FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
W-Agora 4.2.1 - 'profile.php?showuser' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
W-Agora 4.2.1 - 'search.php?search_user' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web Wiz Forums 8.05 - String Filtering SQL Injection
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not p
23RIESGO
abrir ↗Metasploit300
WinDVD7 IASystemInfo.DLL ActiveX Control Buffer Overflow
Stack-based buffer overflow in the IASystemInfo.dll ActiveX control in (1) InterActual Player 2.60.12.0717, (2) Roxio Ci
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
W-Agora 4.2.1 - 'change_password.php?userid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Phone 7940/7960 - 'SIP INVITE' Remote Denial of Service
Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZYXEL Router 3.40 Zynos - SMB Data Handling Denial of Service
ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
W-Agora 4.2.1 - Multiple Arbitrary File Upload Vulnerabilities
Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPX 3.5.15/3.5.16 - 'forums.php' SQL Injection
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core < 2.1.2 - 'PHP_Self' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LedgerSMB1.0/1.1 / SQL-Ledger 2.6.x - 'Login' Local File Inclusion / Authentication Bypass
Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetVIOS Portal - 'page.asp' SQL Injection
SQL injection vulnerability in page.asp in NetVIOS 2.0 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPX 3.5.15/3.5.16 - 'print.php' SQL Injection
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
File(1) 4.13 - Command File_PrintF Integer Underflow
Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execut
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.1.6 - Mb_Parse_Str Function Register_Globals Activation
The mb_parse_str function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 sets the internal register_globals flag and
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.