Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - showHelp '.CHM' File Execution (MS03-004)
Internet Explorer 5.x and 6.0 allows remote attackers to execute arbitrary programs via a modified directory traversal a
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XSOK 1.0 2 - 'LANG Environment' Local Buffer Overrun
Multiple buffer overflows in xsok 1.02 allows local users to gain privileges via (1) a long LANG environment variable, o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alt-N MDaemon 6.x/WorldClient - Form2Raw Raw Message Handler Buffer Overflow (2)
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbi
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alt-N MDaemon 6.x/WorldClient - Form2Raw Raw Message Handler Buffer Overflow (1)
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbi
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - Failure To Log Undocumented TRACK Requests
Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.0.4x mod_php - File Descriptor Leakage (1)
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.0.4x mod_php - File Descriptor Leakage (2)
The mod_php module for the Apache HTTP Server allows local users with write access to PHP scripts to send signals to the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KnowledgeBuilder 2.0/2.1/3.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in KnowledgeBuilder, referred to as KnowledgeBase, allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x - 'Category' SQL Injection
SQL injection vulnerability in PHP-Nuke 6.9 and earlier, and possibly 7.x, allows remote attackers to inject arbitrary S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera Browser 6.0 6 - URI Display Obfuscation
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.6 - 'privmsg.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in privmsg.php in phpBB 2.0.6 allow remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.6 - 'search_id' SQL Injection / MD5 Hash
SQL injection vulnerability in search.php for phpBB 2.0.6 and earlier allows remote attackers to execute arbitrary SQL a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tcpdump 3.x - L2TP Parser Remote Denial of Service
The L2TP protocol parser in tcpdump 3.8.1 and earlier allows remote attackers to cause a denial of service (infinite loo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Eznet 3.5.0 - Remote Stack Overflow Universal
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
osCommerce 2.2 - 'osCsid' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the tep_href_link function in html_output.php for osCommerce before 2.2-MS3
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DameWare Mini Remote Control Server 3.7x - Buffer Overflow (2)
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX B11.11 - '/usr/bin/ct' Format String Privilege Escalation
20RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DameWare Mini Remote Control Server 3.7x - Buffer Overflow (1)
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DameWare Mini Remote Control Server 3.7x - Buffer Overflow (3)
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Messenger Service (French) - Remote (MS03-043)
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allow
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10 - CD9660.Util Probe For Mounting Argument Local Buffer Overflow
Buffer overflow in cd9660.util in Apple Mac OS X 10.0 through 10.3.2 and Apple Mac OS X Server 10.0 through 10.3.2 may a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 / Mozilla 1.2.1 - URI Display Obfuscation (1)
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 / Mozilla 1.2.1 - URI Display Obfuscation (2)
Internet Explorer 5.01 through 6 SP1 allows remote attackers to spoof the domain of a URL via a "%01" character before a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LaGarde StoreFront 5.0 Shopping Cart - 'login.asp' SQL Injection
SQL injection vulnerability in login.asp for StoreFront 6.0, and possibly earlier versions, allows remote attackers to o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FVWM 2.4/2.5 - fvwm-menu-Directory Command Execution
CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local us
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.22 - 'do_brk()' Local Privilege Escalation (2)
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - Workstation Service Remote (MS03-049)
Stack-based buffer overflow in a logging function for Windows Workstation Service (WKSSVC.DLL) allows remote attackers t
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.22 - 'do_brk()' Local Privilege Escalation (1)
Integer overflow in the do_brk function for the brk system call in Linux kernel 2.4.22 and earlier allows local users to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Applied Watch Command Center 1.0 - Authentication Bypass (1)
Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Applied Watch Command Center 1.0 - Authentication Bypass (2)
Applied Watch Command Center allows remote attackers to conduct unauthorized activities without authentication, such as
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.