Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Kerio MailServer 5.6.3 subscribe Module - Overflow
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and po
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kerio MailServer 5.6.3 - Web Mail DO_MAP Module Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kerio MailServer 5.6.3 - Web Mail ADD_ACL Module Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - MSXML XML File Parsing Cross-Site Scripting
Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsof
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Custom HTTP Error HTML Injection
The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in th
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Snitz Forums 2000 3.4.03 - 'search.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to ex
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LedNews 0.7 Post Script - Code Injection
Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a new
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux PAM 0.77 - Pam_Wheel Module 'getlogin() Username' Spoofing Privilege Escalation
pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PMachine 2.2.1 - '/Lib.Inc.php' Remote File Inclusion / Command Execution
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Progress Database 9.1 - Environment Variable Privilege Escalation
Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to g
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader (UNIX) 5.0 6 / Xpdf 0.9x Hyperlinks - Arbitrary Command Execution
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary comma
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Winmail Mail Server 2.3 Build 0402 - Remote Format String
Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cau
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MNOGoSearch 3.1.20 - 'search.cgi?UL' Remote Buffer Overflow (2)
Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul par
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MNOGoSearch 3.1.20 - 'search.cgi?UL' Remote Buffer Overflow (1)
Buffer overflow in search.cgi for mnoGoSearch 3.1.20 allows remote attackers to execute arbitrary code via a long ul par
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
mnoGoSearch 3.1.20 - Remote Command Execution
Buffer overflow in search.cgi for mnoGoSearch 3.2.10 allows remote attackers to execute arbitrary code via a long tmplt
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Atftpd 0.6 - 'atftpdx.c' Remote Command Execution
Buffer overflow in atftp daemon (atftpd) 0.6.1 and earlier, and possibly later versions, allows remote attackers to caus
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.0.45 - 'APR' Crash
Vulnerability in the apr_psprintf function in the Apache Portable Runtime (APR) library for Apache 2.0.37 through 2.0.45
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Object Tag (MS03-020)
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Maxwebportal 1.30 - Remote Database Disclosure
The default installation of MaxWebPortal 1.30 stores the portal database under the web document root with insecure acces
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xaos 3.0 - Language Option Local Buffer Overflow
Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun JRE/SDK 1.x - Untrusted Applet Java Security Model Violation
Sun Java Runtime Environment (JRE) and SDK 1.4.0_01 and earlier allows untrusted applets to access certain information w
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - OBJECT Tag Buffer Overflow
Buffer overflow in Microsoft Internet Explorer 5.01, 5.5, and 6.0 allows remote attackers to execute arbitrary code via
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
kon2 - Local Buffer Overflow (1)
Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
kon2 - Local Buffer Overflow (2)
Buffer overflow in KON kon2 0.3.9b and earlier allows local users to execute arbitrary code via a long -Coding command l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pi3Web 2.0.2 - SortName Buffer Overflow
Pi3Web web server 2.0.2 Beta 1, when the Directory Index is configured to use the "Name" column and sort using the colum
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.3.x/5.1 - 'LSMCODE' Environment Variable Local Buffer Overflow
Buffer overflow in lsmcode in AIX 4.3.3.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - WebDAV Remote Code Execution (2)
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Wind
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebCortex WebStores2000 - SQL Injection
SQL injection vulnerability in browse_items.asp in WebCortex WebStores 2000 6.0 allows remote attackers to gain unauthor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 < 5.1 - Remote Denial of Service
Microsoft Internet Information Services (IIS) 5.0 and 5.1 allows remote attackers to cause a denial of service via a lon
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Make For IBM AIX 4.3.3 - CC Path Local Buffer Overflow
Buffer overflow in GNU make for IBM AIX 4.3.3, when installed setgid, allows local users to gain privileges via a long C
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.