Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.973GitHub PoC 15.478VulnCheck XDB 9069Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
All Enthusiast PhotoPost PHP Pro 5.0 - 'adm-photo.php' Arbitrary Image Manipulation
adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, wh
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PY Software Active Webcam 4.3/5.5 - WebServer Multiple Vulnerabilities
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (CPU consumpti
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Download Center Lite (DCL) 1.5 - Remote File Inclusion
PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'SYS_EPoll_Wait' Local Integer Overflow / Local Privilege Escalation (1)
Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Newsscript - Access Validation
newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YaBB 2.0 - Remote UsersRecentPosts Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in YaBB.pl for YaBB 2.0 RC1 allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 5.x/6.0 - Offline Mode Status Remote Buffer Overflow
Buffer overflow in Yahoo! Messenger allows remote attackers to execute arbitrary code via the offline mode.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
paNews 2.0b4 - Remote Admin Creation SQL Injection
admin_setup.php in paNews 2.0.4b allows remote attackers to inject arbitrary PHP code via the (1) $form[comments] or (2)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
The Includer CGI 1.0 - Remote Command Execution (1)
includer.cgi in The Includer allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the U
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aztek Forum 4.0 - 'myadmin.php' Database Dumper
The export_index action in myadmin.php for Aztek Forum 4.0 allows remote attackers to obtain database files, possibly by
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2003 - Remote Denial of Service
The IPv6 support in Windows XP SP2, 2003 Server SP1, and Longhorn, with Windows Firewall turned off, allows remote attac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer 10 - '.smil' Local Buffer Overflow
Stack-based buffer overflow in the CSmil1Parser::testAttributeFailed function in smlparse.cpp for RealNetworks RealPlaye
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebLog 0.5.3 - Arbitrary File Inclusion
PHP remote file inclusion vulnerability in PHPWebLog 0.5.3 and earlier allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2003 - Remote Denial of Service
Windows Server 2003 and XP SP2, with Windows Firewall turned off, allows remote attackers to cause a denial of service (
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Database 8i/9i - Multiple Directory Traversal Vulnerabilities
Directory traversal vulnerability in Oracle Database Server 8i and 9i allows remote attackers to read or rename arbitrar
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP mcNews 1.3 - 'skinfile' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/header.php in PHP mcNews 1.3 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA License Server - 'GETCONFIG' Remote Buffer Overflow
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execu
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA License Server - 'GETCONFIG' Remote Buffer Overflow
Buffer overflow in Computer Associates (CA) License Client 0.1.0.15 allows remote attackers to execute arbitrary code vi
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PlatinumFTPServer 1.0.18 - Multiple Malformed User Name Connection Denial of Service Vulnerabilities
PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Form Mail 2.3 - Arbitrary File Inclusion
PHP remote file inclusion vulnerability in formmail.inc.php for Form Mail Script 2.3 and earlier allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.0.52 - GET Denial of Service
Apache webserver 2.0.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an HTTP G
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ca3de - Multiple Vulnerabilities
Format string vulnerability in Carsten's 3D Engine (Ca3DE), March 2004 version and earlier, allows remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foxmail 1.1.0.1 - POP3 Temp Dir Stack Overflow
Buffer overflow in Foxmail Server 2.0 allows remote attackers to execute arbitrary code via a long USER command.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProjectBB 0.4.5.1 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AWStats 5.7 < 6.2 - Multiple Remote s
awstats.pl in AWStats 6.3 and 6.4 allows remote attackers to obtain sensitive information by setting the debug parameter
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian Basic 3.0 - '.png' Image Processing Buffer Overflow
Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image fi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
427BB 2.x - Multiple Remote HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPNews 1.2.3/1.2.4 - 'auth.php' Remote File Inclusion
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPCOIN 1.2 - 'mod.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPCOIN 1.2 - 'login.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.