Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
PHP-Nuke 6.5 Addon - 'Viewpage.php' File Disclosure
Absolute path traversal vulnerability in nukestyles.com viewpage.php addon for PHP-Nuke allows remote attackers to read
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.3 - 'socket_iovec_alloc()' Integer Overflow
Integer signedness error in emalloc() function for PHP before 4.3.2 allow remote attackers to cause a denial of service
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - WebDAV Remote
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Wind
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (1)
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Wind
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS - WebDAV 'ntdll.dll' Remote Overflow
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Wind
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AdMan 1.0.20051221 - 'ViewStatement.php' SQL Injection
SQL injection vulnerability in viewStatement.php in AdMan 1.0.20051221 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advanced Poll 2.0 - Remote Information Disclosure
Advanced Poll 2.0.2 allows remote attackers to obtain sensitive information via an HTTP request to info.php, which invok
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Planetmoon - Guestbook Clear Text Password Retrieval
PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XOOPS 2.0 XoopsOption - Information Disclosure
XOOPS 2.0, and possibly earlier versions, allows remote attackers to obtain sensitive information via an invalid xoopsOp
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DCP-Portal 5.3.1 - 'calendar.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Codeworx Technologies DCP-Portal 5.3.1 allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WFChat 1.0 - Information Disclosure
WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ximian Evolution 1.x - MIME image/* Content-Type Data Inclusion
The handle_image function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier does not properly esca
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mambo Site Server 4.0.10 - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php for Mambo Site Server 4.0.10 allows remote attackers to execute sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SIPS 0.2.2 - User Information Disclosure
Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insuff
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 (Windows XP/2000/NT 4.0) - WebDAV 'ntdll.dll' Remote Buffer Overflow (4)
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Wind
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ximian Evolution 1.x - UUEncoding Denial of Service
The try_uudecoding function in mail-format.c for Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attack
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyABraCaDaWeb 1.0 - Full Path Disclosure
MyABraCaDaWeb 1.0.2 and earlier allows remote attackers to obtain sensitive information via an invalid IDAdmin or other
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ximian Evolution 1.x - UUEncoding Parsing Memory Corruption
Ximian Evolution Mail User Agent 1.2.2 and earlier allows remote attackers to cause a denial of service (memory consumpt
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x/2.4.x - Privileged Process Hijacking Privilege Escalation (1)
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 2.2.x - CIFS/9000 Server A.01.x Packet Assembling Buffer Overflow
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multitech RouteFinder 550 - Remote Memory Corruption
Buffer overflow in the web interface for SOHO Routefinder 550 before firmware 4.63 allows remote attackers to cause a de
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Man Program 1.5 - Unsafe Return Value Command Execution
man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Qpopper 4.0.x - Remote Memory Corruption
The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprint
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 3.23.x - 'mysqld' Local Privilege Escalation
MySQL 3.23.55 and earlier creates world-writeable files and allows mysql users to gain root privileges by using the "SEL
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Clearswift MAILsweeper 4.x - MIME Attachment Filter Bypass
Clearswift MAILsweeper 4.x allows remote attackers to bypass attachment detection via an attachment that does not specif
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
File 3.x - Utility Local Memory Allocation
Unknown vulnerability in the "Automatic File Content Type Recognition (AFCTR) Tool version of the file package before 3.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
File 3.x - Local Stack Overflow Code Execution (1)
Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user runn
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
File 3.x - Local Stack Overflow Code Execution (2)
Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user runn
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP JetDirect Printer - SNMP JetAdmin Device Password Disclosure
HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet servic
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sendmail 8.12.x - Header Processing Buffer Overflow (2)
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted addre
45RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.