Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'Timeline.php' SQL Injection
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'Gedrecord.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'login.php?Username' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'Gdbi_interface.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPGedView 2.5/2.6 - 'calendar.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HD Soft Windows FTP Server 1.5/1.6 - 'Username' Format String
Format string vulnerability in HD Soft Windows FTP Server 1.6 and earlier allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 1.4/2.0 - 'module.php' Remote Command Execution
PHP remote file inclusion vulnerability in module.php for ezContents allows remote attackers to execute arbitrary PHP co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Andy's PHP Projects Man Page Lookup Script - Information Disclosure
Directory traversal vulnerability in buildManPage in class.manpagelookup.php for PHP Man Page Lookup 1.2.0 allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Accipiter DirectServer 6.0 - Remote File Disclosure
Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via enc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.23/2.6.0 - 'do_mremap()' Bound Checking Validator (2)
The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Edimax AR-6004 ADSL Router - Management Interface Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the web management interface in Edimax AR-6004 ADSL Routers allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZYXEL ZyWALL 10 Management Interface - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the web management interface in ZyWALL 10 4.07 allows remote attackers to in
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PhpGedView 2.61 - PHPInfo Information Disclosure
admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.23/2.6.0 - 'do_mremap()' Bound Checking Validator (1)
The mremap system call (do_mremap) in Linux kernel 2.4.x before 2.4.21, and possibly other versions before 2.4.24, does
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SnapStream PVS Lite 2.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SnapStream PVS LITE allows remote attackers to inject arbitrary web script o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPGedView 2.61 - Multiple Remote File Inclusions
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php fo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PhpGedView 2.61 - Search Script Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HT
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HotNews 0.x - 'config[incdir]' Remote File Inclusion
PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HotNews 0.x - 'hotnews-engine.inc.php3?config[header]' Remote File Inclusion
PHP remote file inclusion vulnerability in HotNews 0.7.2 and earlier allows remote attackers to execute arbitrary PHP co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Webcam Corp Webcam Watchdog 1.0/1.1/3.63 Web Server - Remote Buffer Overflow
Buffer overflow in the web server of Webcam Watchdog 3.63 allows remote attackers to execute arbitrary code via a long H
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASP-Nuke 1.0/1.2/1.3 - Remote User Database Access
ASP-Nuke 1.3 and earlier places user credentials under the web document root with insufficient access control, which all
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 1.x/2.0.x - 'search.php?search_results' SQL Injection
SQL injection vulnerability in search.php for phpBB 1.0 through 2.0.6 allows remote attackers to execute arbitrary SQL a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreznoShop 1.2.3/1.3 - Search Script Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php for FreznoShop 1.3.0 RC1 and earlier allows remote attackers to i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASPApp PortalApp - Remote User Database Access
PortalApp places user credentials under the web root with insufficient access control, which allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Surfnet 1.31 - CMD_CREDITCARD_CHARGE Denial of Service
Info Touch Surfnet kiosk allows local users to crash Surfnet and access the underlying operating system via the CMD_CRED
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EasyDynamicPages 1.0 - 'config_page.php' PHP Remote File Inclusion
PHP remote file inclusion vulnerability in (1) config.php and (2) config_page.php for EasyDynamicPages 2.0 allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YaSoft Switch Off 2.3 - 'swnet.dll' Remote Buffer Overflow
Stack-based buffer overflow in swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote authenticated users to execu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YaSoft Switch Off 2.3 - Large Packet Remote Denial of Service
swnet.dll in YaSoft Switch Off 2.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XSOK 1.02 - '-xsokdir' Local Buffer Overflow Game
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Athena Web Registration - Remote Command Execution
athenareg.php in Athena Web Registration allows remote attackers to execute arbitrary commands via shell metacharacters
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.