Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
PHP-Nuke 5.6/6.0 - Search Engine SQL Injection
SQL injection vulnerability in PHP-Nuke 5.6 and 6.0 allows remote attackers to execute arbitrary SQL commands via the da
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPBB2 - 'Page_Header.php' SQL Injection
SQL injection vulnerability in page_header.php in phpBB 2.0, 2.0.1 and 2.0.2 allows remote attackers to brute force user
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
cPanel 5.0 - 'Guestbook.cgi' Remote Command Execution (3)
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
cPanel 5.0 - 'Guestbook.cgi' Remote Command Execution (4)
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux-ATM LES 2.4 - Command Line Argument Buffer Overflow
Buffer overflow in les for ATM on Linux (linux-atm) before 2.4.1, if used setuid, allows local users to gain privileges
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Forum 1 - 'footer' Remote File Inclusion
PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Forum 1 - 'header' Remote File Inclusion
PHP remote file inclusion vulnerability in D-Forum 1.00 through 1.11 allows remote attackers to execute arbitrary PHP co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eCommerce Corporation Online Store Kit 3.0 - 'More.php?id' SQL Injection
SQL injection vulnerability in Online Store Kit 3.0 allows remote attackers to inject arbitrary SQL and gain unauthorize
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eCommerce Corporation Online Store Kit 3.0 - 'More.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in more.php for Online Store Kit 3.0 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Board 1.0 - User Password Disclosure
login.php in php-Board 1.0 stores plaintext passwords in $username.txt with insufficient access control under the web do
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DotBr 0.1 - 'System.php3' Remote Command Execution
DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) syst
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DotBr 0.1 - 'Exec.php3' Remote Command Execution
DotBr 0.1 allows remote attackers to execute arbitrary shell commands via the cmd parameter to (1) exec.php3 or (2) syst
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 10.x - stmkfont Alternate Typeface Library Buffer Overflow (1)
Buffer overflow in stmkfont utility of HP-UX 10.0 through 11.22 allows local users to gain privileges via a long command
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.3.3/5.1/5.2 - 'libIM' Buffer Overflow
Buffer overflow in libIM library (libIM.a) for National Language Support (NLS) on AIX 4.3 through 5.2 allows local users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 10.x - rs.F3000 Unauthorized Access
rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while op
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT/2000 - 'cmd.exe' CD Buffer Overflow (PoC)
Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argumen
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RARLAB FAR 1.65/1.70 - File Manager Buffer Overflow
Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ericsson HM220dp DSL Modem - World Accessible Web Administration Interface
The web administration page for the Ericsson HM220dp ADSL modem does not require authentication, which could allow remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nethack 3 - Local Buffer Overflow (3)
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netgear FM114P Wireless Firewall - File Disclosure
Directory traversal vulnerability in the web configuration interface in Netgear FM114P 1.4 allows remote attackers to re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nethack 3 - Local Buffer Overflow (2)
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nethack 3 - Local Buffer Overflow (1)
Buffer overflow in (1) nethack 3.4.0 and earlier, and (2) falconseye 1.9.3 and earlier, which is based on nethack, allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 6.0/7.0 - 'Username' URI Warning Dialog Buffer Overflow
Buffer overflow in Opera 6.05 and 6.06, and possibly other versions, allows remote attackers to execute arbitrary code v
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cedric Email Reader 0.4 - Global Configuration Script Remote File Inclusion
PHP remote file inclusion vulnerability in emailreader_execute_on_each_page.inc.php in Cedric Email Reader 0.4 allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cedric Email Reader 0.2/0.3 - Skin Configuration Script Remote File Inclusion
PHP remote file inclusion vulnerability in email.php (aka email.php3) in Cedric Email Reader 0.2 and 0.3 allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HPUX 10.20/11 Wall Message - Local Buffer Overflow
Buffer overflow in wall for HP-UX 10.20 through 11.11 may allow local users to execute arbitrary code by calling wall wi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Celestial Software AbsoluteTelnet 2.0/2.11 - Title Bar Buffer Overflow
Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window t
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Epic Games Unreal Engine 436 - Client Unreal URL Denial of Service
Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Epic Games Unreal Engine 436 - URL Directory Traversal
Directory traversal vulnerability in Unreal Tournament Server 436 and earlier allows remote attackers to access known fi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - Redirector Privilege Escalation
Buffer overflow in the Windows Redirector function in Microsoft Windows XP allows local users to execute arbitrary code
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.