Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Web Wiz Forum 6.34/7.0/7.5 - Unauthorized Private Forum Access
post_message_form.asp in Web Wiz Forums 6.34 through 7.5, when quote mode is used, allows remote attackers to read or wr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VieNuke VieBoard 2.6 - SQL Injection
SQL injection vulnerability in viewtopic.asp in VieBoard 2.6 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IA WebMail Server 3.0/3.1 - GET Buffer Overrun
Stack-based buffer overflow in IA WebMail Server 3.1.0 allows remote attackers to execute arbitrary code via a long GET
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synthetic Reality SymPoll 1.5 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Sympoll 1.5 allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MPM Guestbook 1.2 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in MPM Guestbook 1.2 allows remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nullsoft SHOUTcast 1.9.2 - 'icy-name/icy-url' Memory Corruption (1)
Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name foll
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nullsoft SHOUTcast 1.9.2 - 'icy-name/icy-url' Memory Corruption (2)
Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name foll
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPKit 1.6 - 'Include.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MathoPD 1.x - Remote Buffer Overflow
Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BRS Webweaver 1.06 - HTTPd 'User-Agent' Remote Denial of Service
Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
http commander 4.0 - Directory Traversal
Directory traversal vulnerability in (1) Openfile.aspx and (2) Html.aspx in HTTP Commander 4.0 allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DATEV Nutzungskontrolle 2.1/2.2 - Unauthorized Access
DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BEA WebLogic 6/7/8 - InteractiveQuery.jsp Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seyeon FlexWATCH Network Video Server 2.2 - Unauthorized Administrative Access
FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MLdonkey 2.5-4 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Metaframe XP - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to injec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tritanium Scripts Tritanium Bulletin Board 1.2.3 - Unauthorized Access
index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ledscripts LedForums - Multiple HTML Injections
Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inj
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BEA Tuxedo 6/7/8 and WebLogic Enterprise 4/5 - Input Validation
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files ou
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Serious Sam Engine 1.0.5 - Remote Denial of Service
Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
E107 - 'Chatbox.php' Denial of Service
chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fastream NetFile 6.0.3.588 - Error Message Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
kpopup 0.9.x - Privileged Command Execution
misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their priv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Centrinity FirstClass HTTP Server 7.1 - Directory Disclosure
Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 5.6 - File Transfer Buffer Overrun
Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send req
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chi Kien Uong Guestbook 1.51 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Apache 2.0.40 - Directory Index Default Configuration Error
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SH-HTTPD 0.3/0.4 - Character Filtering Remote Information Disclosure
Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a G
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Musicqueue 0.9/1.0/1.1 - Multiple Buffer Overrun Vulnerabilities
Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the con
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
thttpd 2.2x - 'defang' Remote Buffer Overflow (PoC)
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.