Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x 'Reviews' Module - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Shaun2k2 Palmhttpd Server 3.0 - Remote Denial of Service
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - HCP URI Handler Arbitrary Command Execution
Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" ar
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 2.2.8 (Linux Kernel 2.6 / Debian / Mandrake) - Share Privilege Escalation
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x - Public Message SQL Injection
SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ClamAV Daemon 0.65 - UUEncoded Message Denial of Service
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail mes
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - LoadPicture File Enumeration
Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BolinTech DreamFTP Server 1.0 - User Name Format String
Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenJournal 2.0 - Authentication Bypassing
oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux VServer Project 1.2x - Chroot Breakout
Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mambo Open Source 4.6 - 'Itemid' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xlight FTP Server 1.x - Long Directory Request Remote Denial of Service
Xlight 1.52, with log to screen enabled, allows remote attackers to cause a denial of service by requesting a long direc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BSD - SHMAT System Call Privilege Escalation
The shmat system call in the System V Shared Memory interface for FreeBSD 5.2 and earlier, NetBSD 1.3 and earlier, and O
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Discuz! 2.0/3.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Discuz! Board 2.x and 3.x allows remote attackers to execute arbitrary scrip
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web Crossing Web Server 4.0/5.0 Component - Remote Denial of Service
Web Crossing 4.x and 5.x allows remote attackers to cause a denial of service (crash) by sending a HTTP POST request wit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
All Enthusiast ReviewPost PHP Pro 2.5 - 'showproduct.php' SQL Injection
Multiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
All Enthusiast ReviewPost PHP Pro 2.5 - 'showcat.php' SQL Injection
Multiple SQL injection vulnerabilities in ReviewPost PHP Pro allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RXGoogle.CGI 1.0/2.5 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in rxgoogle.cgi allows remote attackers to execute arbitrary script as other us
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - URL Injection in History List (MS04-004)
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL i
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cauldron Chaser 1.4/1.5 - Remote Denial of Service (1)
The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exceptio
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cauldron Chaser 1.4/1.5 - Remote Denial of Service (2)
The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exceptio
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Qualiteam X-Cart 3.x - Multiple Remote Information Disclosure Vulnerabilities
X-Cart 3.4.3 allows remote attackers to gain sensitive information via a mode parameter with (1) phpinfo command or (2)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 12 MSFC2 - Layer 2 Frame Denial of Service
Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.x - 'Export.php' File Disclosure
Directory traversal vulnerability in export.php in phpMyAdmin 2.5.5 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPX 3.2.3 - Multiple Vulnerabilities
PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Qualiteam X-Cart 3.x - 'upgrade.php?perl_binary' Arbitrary Command Execution
X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Qualiteam X-Cart 3.x - 'general.php?perl_binary' Arbitrary Command Execution
X-Cart 3.4.3 allows remote attackers to execute arbitrary commands via the perl_binary argument in (1) upgrade.php or (2
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Niti Telecom Caravan Business Server 2.00-03D - Directory Traversal
Directory traversal vulnerability in sample_showcode.html in Caravan 2.00/03d and earlier allows remote attackers to rea
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Crob FTP Server 3.5.1 - Denial of Service
Crob FTP Server 3.5.1 allows remote authenticated users to cause a denial of service (crash) via a dir command with a la
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
0verkill 0.16 - Game Client Multiple Local Buffer Overflow Vulnerabilities
Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the clien
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.