Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.000exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.498VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Orenosv HTTP/FTP Server 0.5.9 - GET Denial of Service (1)
Orenosv 0.5.9f allows remote attackers to cause a denial of service (crash) via a long HTTP GET request.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netgear RP114 3.26 - Content Filter Bypass
Netgear RP114 allows remote attackers to bypass the keyword based URL filtering by requesting a long URL, as demonstrate
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VocalTec VGW120/VGW480 Telephony Gateway Remote H.225 - Denial of Service
Unknown vulnerability in the ASN.1/H.323/H.225 stack of VocalTec VGW120 and VGW480 allows remote attackers to cause a de
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
cPanel 5 < 9 - Local Privilege Escalation
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path optio
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mollensoft Lightweight FTP Server 3.6 - Remote Denial of Service
Buffer overflow in Mollensoft Lightweight FTP Server 3.6 allows remote authenticated users to cause a denial of service
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Liferay Enterprise Portal 1.x/2.x/5.0.2 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in index.jsp for Liferay before 2.2.0 release 10/1/2004 allow remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
e107 Website System 0.5/0.6 - 'Log.php' HTML Injection
Cross-site scripting (XSS) vulnerability in stats.php in e107 allows remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape Navigator 7.1 - Embedded Image URI Obfuscation
Netscape Navigator 7.1 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LHA 1.x - 'extract_one' Multiple Buffer Overflow Vulnerabilities
Buffer overflow in the extract_one function from lhext.c in LHA may allow attackers to execute arbitrary code via a long
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Subversion 1.0.2 - Date Overflow (Metasploit)
Stack-based buffer overflow during the apr_time_t data conversion in Subversion 1.0.2 and earlier allows remote attacker
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ActivePerl 5.x / Cygwin 1.5.x - System Function Call Buffer Overflow
ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
dsm light Web file browser 2.0 - Directory Traversal
Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ActivePerl 5.x / Larry Wall Perl 5.x - Duplication Operator Integer Overflow
Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE Konqueror 3.x - Embedded Image URI Obfuscation
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x - 'Modpath' File Inclusion
PHP remote file inclusion vulnerability in index.php in Php-Nuke 6.x through 7.3 allows remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WGet 1.x - Insecure File Creation Race Condition
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being do
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - Self-Executing Folder
Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file c
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.3.x - Help Protocol Remote Code Execution
HelpViewer in Mac OS X 10.3.3 and 10.2.8 processes scripts that it did not initiate, which can allow attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 1.0/2.x/3.0 - 'index.php' User Interface Spoofing
Cross-site scripting (XSS) vulnerability in index.php in Jelsoft vBulletin allows remote attackers to spoof parts of a w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
osCommerce 2.x - File Manager Directory Traversal
Directory traversal vulnerability in file_manager.php in osCommerce 2.2 allows remote attackers to view arbitrary files
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TurboTrafficTrader C 1.0 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Turbo Traffic Trader C (TTT-C) 1.0 allow remote attackers to inje
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Multiple Firewall - DNS Response Denial of Service
The SYMDNS.SYS driver in Symantec Norton Internet Security and Professional 2002 through 2004, Norton Personal Firewall
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - http-equiv Meta Tag Denial of Service
Internet Explorer 6 allows remote attackers to cause a denial of service (crash) via Javascript that creates a new popup
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 2003 - Mail Client E-mail Address Verification
Outlook 2003 allows remote attackers to bypass intended access restrictions and cause Outlook to request a URL from a re
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetBSD/FreeBSD Port Systrace 1.x - Exit Routine Access Validation Privilege Escalation
The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4/5/6 - Embedded Image URI Obfuscation
Unknown versions of Internet Explorer and Outlook allow remote attackers to spoof a legitimate URL in the status bar via
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
National Science Foundation Squid Proxy 2.3 - Internet Access Control Bypass
Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 2003 - Predictable File Location
Outlook 2003, when replying to an e-mail message, stores certain files in a predictable location for the "src" of an img
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MailEnable Mail Server HTTPMail 1.x - Remote Heap Overflow
Buffer overflow in MEHTTPS (HTTPMail) of MailEnable Professional 1.5 through 1.7 allows remote attackers to cause a deni
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adam Webb NukeJokes 1.7/2.0 Module - 'modules.php?jokeid' SQL Injection
SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.