Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Microsoft Access 97/2000/2002 Snapshot Viewer - ActiveX Control Parameter Buffer Overflow
Buffer overflow in the ActiveX control for Microsoft Access Snapshot Viewer for Access 97, 2000, and 2002 allows remote
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft WordPerfect - Converter Buffer Overrun
Buffer overflow in Microsoft Wordperfect Converter allows remote attackers to execute arbitrary code via modified data o
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Basic For Applications SDK 5.0/6.0/6.2/6.3 - Document Handling Buffer Overrun
Heap-based buffer overflow in VBE.DLL and VBE6.DLL of Microsoft Visual Basic for Applications (VBA) SDK 5.0 through 6.3
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 - Information Disclosure
wgate.dll in SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote attackers to obtain potentially sensiti
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
sap internet transaction server 4620.2.0.323011 build 46b.323011 - Directory Traversal
Directory traversal vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP Internet Transaction Server 4620.2.0.323011 Build 46B.323011 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in wgate.dll for SAP Internet Transaction Server (ITS) 4620.2.0.323011 allows r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux pam_lib_smb < 1.1.6 - '/bin/login' Remote Overflow
Buffer overflow in PAM SMB module (pam_smb) 1.1.6 and earlier, when authenticating to a remote service, allows remote at
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GtkFtpd 1.0.4 - Remote Buffer Overflow
Buffer overflow in sys_cmd.c for gtkftpd 1.0.4 and earlier allows remote attackers to execute arbitrary code by creating
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eNdonesia 8.2/8.3 - 'Mod' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in mod.php in eNdonesia 8.2 allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tellurian TftpdNT 1.8/2.0 - 'Filename' Buffer Overrun
Buffer overflow in Tellurian TftpdNT 1.8 allows remote attackers to execute arbitrary code via a TFTP request with a lon
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Attila PHP 3.0 - SQL Injection Unauthorized Privileged Access
SQL injection vulnerability in global.php3 of AttilaPHP 3.0, and possibly earlier versions, allows remote attackers to b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Real Server 7/8/9 (Windows / Linux) - Remote Code Execution
Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetwor
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OptiSoft Blubster 2.5 - Remote Denial of Service
Blubster 2.5 allows remote attackers to cause a denial of service (crash) via a flood of connections to UDP port 701.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Avant Browser 8.0.2 - 'HTTP Request' Buffer Overflow (PoC)
Buffer overflow in Avant Browser 8.02 allows remote attackers to cause a denial of service (crash) and possibly execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Object Data Remote (MS03-032)
Buffer overflow in Internet Explorer 6 SP1 for certain languages that support double-byte encodings (e.g., Japanese) all
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RealOne Player 1.0/2.0/6.0.10/6.0.11 - '.SMIL' File Script Execution
RealOne player allows remote attackers to execute arbitrary script in the "My Computer" zone via a SMIL presentation wit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DameWare Mini Remote Control Server - System
Buffer overflow in DameWare Mini Remote Control before 3.73 allows remote attackers to execute arbitrary code via a long
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle XDB FTP Service - UNLOCK Buffer Overflow
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 earch Module - 'PDA_limit' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPOutSourcing Zorum 3.x - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php for Zorum 3.4 and 3.5 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - DCOM RPC Interface Buffer Overrun
Buffer overflow in a certain DCOM interface for RPC in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPOutsourcing Zorum 3.4 - Full Path Disclosure
index.php for Zorum 3.4 allows remote attackers to determine the full path of the web root via invalid parameter names,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Website 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - SQL Injection
SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.2 - Remote Command Execution
Off-by-one error in the fb_realpath() function, as derived from the realpath function in BSD, may allow attackers to exe
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 Calendar Module - 'day' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 pagemaster Module - 'PAGE_id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.7.3/0.8.2/0.8.3/0.9.2 fatcat Module - 'fatcat_id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 12.x/11.x - HTTP Remote Integer Overflow
Buffer overflow in the HTTP server for Cisco IOS 12.2 and earlier allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (2)
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, wit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Informix Dynamic Server 9.40/Informix Extended Parallel Server 8.40 - Multiple Vulnerabilities (1)
Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, wit
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.