Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Epic Games Unreal Engine 436 - Client Unreal URL Denial of Service
Buffer overflow in Epic Games Unreal Engine 226f through 436 allows remote attackers to cause a denial of service (crash
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ByteCatcher FTP Client 1.0.4 - 'Server Banner' Buffer Overflow
Buffer overflow in ByteCatcher FTP client 1.04b allows remote attackers to cause a denial of service (crash) and possibl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Electrasoft 32Bit FTP 9.49.1 - Client Long Server Banner Buffer Overflow
Buffer overflow in the 32bit FTP client 9.49.1 allows remote attackers to cause a denial of service (crash) and possibly
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TOPO 1.41 - Full Path Disclosure
TOPo 1.43 allows remote attackers to obtain sensitive information by sending an HTTP request with an invalid parameter t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPMyShop 1.0 - 'compte.php' SQL Injection
SQL injection vulnerability in compte.php in PhpMyShop 1.00 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 5.x/6.0 - Avatar HTML Injection
Cross-site scripting (XSS) vulnerability in the Your_Account module for PHP-Nuke 5.0 through 6.0 allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 2.x/3.x - CHPass Temporary File Link File Content Revealing
chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a tem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sambar Server 5.x - Open Proxy / Authentication Bypass
HTTP Proxy in Sambar Server before 6.0 beta 6, when security.ini lacks a 127.0.0.1 proxydeny entry, allows remote attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nukebrowser 2.x - Remote File Inclusion
PHP remote file inclusion vulnerability in nukebrowser.php in Nukebrowser 2.1 to 2.5 allows remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BitchX 1.0 - 'RPL_NAMREPLY' Denial of Service
BitchX 75p3 and 1.0c16 through 1.0c20cvs allows remote attackers to cause a denial of service (segmentation fault) via a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Solaris 2.5/2.6/7.0/8/9 AT Command - Arbitrary File Deletion
A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r arg
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 3.x - Null Byte Directory / File Disclosure
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FTLS Guestbook 1.1 - Script Injection
Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Mailman 2.1 - Error Page Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
slocate 2.5/2.6 - Local Buffer Overrun
Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Mailman 2.1 - 'email' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
List Site Pro 2.0 - User Database Delimiter Injection
List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field de
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Locator Service Buffer Overflow
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MTink 0.9.x - Printer Status Monitor Environment Variable Buffer Overflow
Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CVS 1.11.x - Directory Request Double-Free Heap Corruption
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly ex
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GameSpy 3D 2.62 - Packet Amplification Denial of Service
Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.3 - 'privmsg.php' SQL Injection
SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Virus Control System 1.8 - Information Disclosure
Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro OfficeScan 3.x - CGI Directory Insufficient Permissions
The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentica
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro ScanMail For Exchange 3.8 - Authentication Bypass
Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.ex
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Virus Control System 1.8 - Denial of Service
Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GLIBC locale - Format Strings
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Geeklog 1.3.7 - 'profiles.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Geeklog 1.3.7 - 'comment.php?cid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Geeklog 1.3.7 - 'Homepage User' HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.