Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.973GitHub PoC 15.478VulnCheck XDB 9069Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
PowerPortal 1.1/1.3 - Private Message HTML Injection
Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fusionphp Fusion News 3.3/3.6 - Administrator Command Execution
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Verylost LostBook 1.1 - Message Entry HTML Injection
Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jaws 0.2/0.3/0.4 - 'ControlPanel.php' SQL Injection
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AntiBoard 0.6/0.7 - 'antiboard.php?feedback' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inje
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Phorum 5.0.7 - Search Script Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX - Panther Internet Connect Privilege Escalation
PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDia
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AntiBoard 0.6/0.7 - 'antiboard.php' Multiple SQL Injections
SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera Web Browser 7.53 - Location Replace URI Obfuscation
A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RiSearch 0.99 /RiSearch Pro 3.2.6 - show.pl Arbitrary File Access
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RiSearch 0.99 /RiSearch Pro 3.2.6 - show.pl Open Proxy Relay
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XLineSoft ASPRunner 1.0/2.x - '[TABLE]_list.asp?searchFor' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Browser 0.8/0.9/1.x - Refresh Security Property Spoofing
Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Jav
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XLineSoft ASPRunner 1.0/2.x - '[TABLE-NAME]_search.asp?Typeen' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XLineSoft ASPRunner 1.0/2.x - Database Direct Request Information Disclosure
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XLineSoft ASPRunner 1.0/2.x - '[TABLE-NAME]_edit.asp?SQL' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XLineSoft ASPRunner 1.0/2.x - 'export.asp?SQL' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EasyIns Stadtportal 4.0 - 'Site' Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows SMS 2.0 - Denial of Service
The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EasyWeb 1.0 FileManager Module - Directory Traversal
Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Denial of Service
mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a ta
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache - Arbitrary Long HTTP Headers (Denial of Service)
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memor
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 3.0.4 - SWAT Authorisation Buffer Overflow
Buffer overflow in the Samba Web Administration Tool (SWAT) in Samba 3.0.2 to 3.0.4 allows remote attackers to execute a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Flash FTP Server - Directory Traversal
Directory traversal vulnerability in Net2Soft Flash FTP Server 1.0 allows remote attackers to read and create arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lexmark Multiple HTTP Servers - Denial of Service
The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Conceptronic CADSLR1 Router - Denial of Service
The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Layton Technology HelpBox 3.0.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Layton HelpBox 3.0.1 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Serena TeamTrack 6.1.1 - Remote Authentication Bypass
Serena TeamTrack 6.1.1 allows remote attackers to obtain sensitive information such as user names, versions, and databas
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetSupport DNA HelpDesk 1.0 Problist Script - SQL Injection
SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Leigh Business Enterprises Web HelpDesk 4.0 - SQL Injection
SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remot
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.