Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
PHP Hosting Biller 1.0 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Php Hosting Biller 1.0 allows remote attackers to inject arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
gMotor2 Game Engine - Multiple Vulnerabilities
Multiple buffer overflows in Image Space rFactor 1.250 and earlier allow remote attackers to execute arbitrary code via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Toribash 2.x - Multiple Vulnerabilities
Format string vulnerability in the server in Toribash 2.71 and earlier allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Text File Search Classic - 'TextFileSearch.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in textfilesearch.asp in the Text File Search ASP (Classic) edition allows remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 12.3 - Show IP BGP Regexp Remote Denial of Service
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to cause a denial of service
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Diskeeper 9 - Remote Memory Disclosure
The administrative interface (aka DkService.exe) in Diskeeper 9 Professional, 2007 Pro Premier, and probably other versi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BlueCat Networks Adonis 5.0.2.8 - CLI Privilege Escalation
The Command Line Interface (CLI), aka Adonis Administration Console, on the BlueCat Networks Adonis DNS/DHCP appliance 5
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java Runtime Environment 1.4.2 - Font Parsing Privilege Escalation
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JR
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 8.1 - 'KDU_V32M.DLL' Remote Denial of Service
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denia
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zoidcom 0.6.x - Malformed Packet Denial of Service
Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (ak
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 6.0.13 - Insecure Cookie Handling Quote Delimiter Session ID Disclosure
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Vector Markup Language 'VGX.dll' Remote Buffer Overflow
Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in In
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft XML Core Services 6.0 - SubstringData Integer Overflow
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringD
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 6.0.13 - Host Manager Servlet Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OWASP Stinger - Filter Bypass
OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 1.0.7 - 'Pool index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in the Pool 1.0.7 theme for WordPress allows remote attackers to i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Savant Web Server 3.1 - GET Universal Remote Overflow
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Stats 0.1.9.2 - 'WhoIs.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lib2 PHP Library 0.2 - 'My_Statistics.php' Remote File Inclusion
PHP remote file inclusion vulnerability in adm/my_statistics.php in Omnistar Lib2 PHP 0.2 allows remote attackers to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Haudenschilt Family Connections 0.8 - 'index.php' Authentication Bypass
index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary accou
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZYXEL ZyWALL 2 3.62 - '/Forms/General_1?sysSystemName' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bilder Galerie 1.0 - 'index.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Generic Software Wrappers Toolkit 1.6.3 (GSWTK) - Race Condition Privilege Escalation
Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Systrace - Multiple System Call Wrappers Concurrency Vulnerabilities
Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.2.3 - 'snmpget()' object id Local Buffer Overflow (EDI)
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Shoutbox 1.0 - 'Shoutbox.php' Remote File Inclusion
PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mapos-Scripts.de Gastebuch 1.5 - 'index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in Gaestebuch 1.5 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS Next Hop Resolution Protocol (NHRP) - Denial of Service
Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote at
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
File Uploader 1.1 - 'index.php?config[root_ordner]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
File Uploader 1.1 - 'datei.php?config[root_ordner]' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.