Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.542VulnCheck XDB 9091Nuclei 4434Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
vBulletin 2.0/2.2.x - 'memberlist.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zeroo HTTP Server 1.5 - Directory Traversal (1)
Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Java! JustInTime Compiler 210.65 - Command Execution
Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Java Virtual Machine 3802 Series - Bytecode Verifier
The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Int
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TFTPD32 2.50 - 'Filename' Remote Buffer Overflow
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filenam
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mhonarc 2.5.x - Mail Header HTML Injection
Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TFTPD32 2.50 - Arbitrary File Download/Upload
tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MailEnable 1.501x - Email Server Buffer Overflow
MailEnable 1.5 015 through 1.5 018 allows remote attackers to cause a denial of service (crash) via a long USER string,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lonerunner Zeroo HTTP Server 1.5 - Remote Buffer Overflow
Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary cod
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Perception LiteServe 2.0 - CGI Source Disclosure
Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP requ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IISPop 1.161/1.181 - Remote Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Key Focus KF Web Server 1.0.8 - Directory Traversal
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recog
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LibHTTPD 1.2 - POST Buffer Overflow
Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB Advanced Quick Reply Hack 1.0/1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ISC BIND 8.3.x - OPT Record Large UDP Denial of Service
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Traceroute-nanog 6 - Local Buffer Overflow
Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Light HTTPd 0.1 - 'GET' Buffer Overflow (1)
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET reques
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
W3Mail 1.0.6 - File Disclosure
Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Light HTTPd 0.1 - 'GET' Buffer Overflow (2)
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET reques
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EZ Systems HTTPBench 1.1 - Information Disclosure
ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hotfoon Dialer 4.0 - Buffer Overflow (PoC)
Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Perception LiteServe 2.0.1 - DNS Wildcard Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Web Server 0.5.1 - File Disclosure
Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNX RTOS 6.2 - Application Packager Non-Explicit Path Execution
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zeus Web Server 4.0/4.1 - Admin Interface Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Perception LiteServe 2.0.1 - Directory Query String Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lotus Domino 5.0.8-9 - Non-Existent NSF Database Banner Information Disclosure
Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obt
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pine 4.x - 'From:' Heap Corruption
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteCast 1.2 - User Credential Disclosure
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP CIFS/9000 Server A.01.05/A.01.06 - Local Buffer Overflow
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, all
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.