Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.973GitHub PoC 15.478VulnCheck XDB 9069Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Scrapland 1.0 - Server Termination Denial of Service
Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an err
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Einstein 1.01 - Local Password Disclosure (ASM)
Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BadBlue 2.5 - Easy File Sharing Remote Buffer Overflow
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eXeem 0.21 - Local Password Disclosure (ASM)
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local use
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.2 - File Globbing Denial of Service
The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KNet Web Server 1.04c - Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possib
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CubeCart 2.0.x - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP f
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Avaya IP Office Phone Manager - Local Password Disclosure
The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.6 - 'select_server.lib.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.6 - 'theme_left.css.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
webconnect 6.4.4 < 6.5 - Directory Traversal / Denial of Service
Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows rem
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.6 - 'theme_right.css.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.6 - 'display_tbl_links.lib.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Soldier of Fortune 2 1.03 - 'cl_guid' Server Crash
Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PunBB 3.0/3.1 - Multiple Remote Input Validation Vulnerabilities
Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Winace UnAce 1.x - ACE Archive Directory Traversal
Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chat Anywhere 2.72a - Local Password Disclosure
Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PeerFTP 5 - Local Password Disclosure
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0.6 - PHP Code Injection
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SendLink 1.5 - Local Password Disclosure
SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eXeem 0.21 - Local Password Disclosure
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local use
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Invision Power Board (IP.Board) 1.x/2.0.3 - SML Code Script Injection
Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PMachine Pro 2.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Thomson TCW690 Cable Modem ST42.03.0a - GET Denial of Service
The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a deni
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Thomson TCW690 - POST Password Validation
The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SHOUTcast 1.9.4 (Windows) - File Request Format String Remote Overflow
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash)
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Medal of Honor Spearhead (Linux) - Server Remote Buffer Overflow
Buffer overflow in Medal of Honor (1) Allied Assault 1.11v9 and earlier, (2) Breakthrough 2.40b and earlier, and (3) Spe
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Knox Arkeia Server Backup 5.3.x - Remote Code Execution
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a l
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3Com 3CDaemon FTP - Unauthorized 'USER' Remote Buffer Overflow
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Knox Arkeia Backup Client 5.3.3 Type 77 (OSX) - Overflow (Metasploit)
Stack-based buffer overflow in Knox Arkeia Server Backup 5.3.x allows remote attackers to execute arbitrary code via a l
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.