Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
ProductCart 1.x/2.x - Weak Cryptography
EarlyImpact ProductCart uses a weak encryption scheme to encrypt passwords, which allows remote attackers to obtain the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RobotFTP Server 1.0/2.0 - 'Username' Buffer Overflow (2)
Buffer overflow in RobotFTP 1.0 and 2.0 beta 1 allows remote attackers to cause a denial of service (crash) and possibly
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProductCart 1.x/2.x - 'advSearch_h.asp' Multiple SQL Injections
Multiple SQL injection vulnerabilities in ProductCart 2.7 allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ACLogic CesarFTP 0.99 - Remote Resource Exhaustion (Denial of Service)
CesarFTP 0.99e allows remote attackers to cause a denial of service (CPU consumption) via a long RETR parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xlight FTP Server 1.52 - Remote Send File Request Denial of Service
Xlight FTP server 1.52 allows remote authenticated users to cause a denial of service (crash) via a RETR command with a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YABB SE 1.5 - 'Quote' SQL Injection
SQL injection vulnerability in post.php for YaBB SE 1.5.4 and 1.5.5 allows remote attackers to obtain hashed passwords v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AllMyLinks 0.x - 'footer.inc.php' Arbitrary Code Execution
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2) AllMyLinks, and (3) AllMyG
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CitrusDB 0.3.6 - Remote Authentication Bypass
CitrusDB 0.3.6 and earlier generates easily predictable MD5 hashes of the user name for the id_hash cookie, which allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - ASN.1 'LSASS.exe' Remote Denial of Service (MS04-007)
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microso
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sami FTP Server 1.1.3 - Invalid Command Argument Local Denial of Service
The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - ITS Protocol Zone Bypass (MS04-013)
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KarjaSoft Sami HTTP Server 1.0.4 - GET Buffer Overflow
Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and pos
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sami FTP Server 1.1.3 - Library Crafted GET Remote Denial of Service
The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsyste
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
rsync 2.5.7 - Local Stack Overflow / Local Privilege Escalation
Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a de
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Crob FTP Server 3.5.2 - Remote Denial of Service
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disco
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XFree86 4.x - CopyISOLatin1Lowered Font_Name Buffer Overflow
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Macallan Mail Solution Macallan Mail Solution 2.8.4.6 (Build 260) - Web Interface Authentication Bypass
Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authenticat
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 1.x/2.0 - 'db.php' Arbitrary File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Monkey HTTP Daemon 0.x - Missing Host Field Denial of Service
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BolinTech DreamFTP Server 1.2 (1.02/TryFTP 1.0.0.1) - Remote User Name Format String
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 1.x/2.0 - 'archivednews.php' Arbitrary File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BosDev BosDates 3.x - SQL Injection
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EvolutionX - Multiple Remote Buffer Overflow Vulnerabilities
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Maxwebportal 1.3x - 'down.asp' HTTP_REFERER Cross-Site Scripting
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web scri
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Maxwebportal 1.3x - Personal Message 'SendTo' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web scri
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Caucho Technology Resin 2.1.12 - Directory Listings Disclosure
Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-I
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ClamAV Daemon 0.65 - UUEncoded Message Denial of Service
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail mes
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sambar Server 6.0 - 'results.stm' POST Buffer Overflow
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers t
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x - Public Message SQL Injection
SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.