Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.542VulnCheck XDB 9091Nuclei 4434Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Symantec Norton Personal Firewall 2002/Kaspersky Labs Anti-Hacker 1.0/BlackIce Server Protection 3.5/BlackICE Defender 2.9 - Auto Block Denial of Service
Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Help Facility ActiveX Control Buffer Overflow
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edi
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Killer Protection 1.0 - Information Disclosure
Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ghttpd 1.4.x - 'Log()' Remote Buffer Overflow
Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are pas
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9i Application Server 9.0.2 Web Cache Administration Tool - Denial of Service
The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cau
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cooolsoft PowerFTP Server 2.x - Remote Denial of Service (1)
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of s
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ATP HTTPd 0.4 - Single Byte Buffer Overflow
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers
48RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cooolsoft PowerFTP Server 2.x - Remote Denial of Service (2)
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of s
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cooolsoft PowerFTP Server 2.x - Remote Denial of Service (3)
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of s
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpLinkat 0.1 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyNewsletter 0.6.10 - Remote File Inclusion
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Py-Membres 3.1 - 'index.php' Unauthorized Access
index.php in Py-Membres 3.1 allows remote attackers to log in as an administrator by setting the pymembs parameter to "a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TightAuction 3.0 - Config.INC Information Disclosure
TightAuction 3.0 stores config.inc under the web document root with insufficient access control, which allows remote att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Midicart PHP - Information Disclosure
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jetty 3.1.6/3.1.7/4.1 Servlet Engine - Arbitrary Command Execution
Directory traversal vulnerability in the CGIServlet for Jetty HTTP server before 4.1.0 allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Midicart PHP - Arbitrary File Upload
MidiCart PHP, PHP Plus, and PHP Maxi allows remote attackers to (1) upload arbitrary php files via a direct request to a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3/2.0.x - Server Side Include Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26,
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySimpleNews 1.0 - Remote Readable Administrator Password
The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.8.3 - 'article.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySimpleNews 1.0 - PHP Injection
Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code an
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SurfControl SuperScout WebFilter for Windows 2000 - SQL Injection
SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SurfControl SuperScout WebFilter for Windows 2000 - File Disclosure
Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sendmail 8.12.x - SMRSH Double Pipe Access Validation
Sendmail Consortium's Restricted Shell (SMRSH) in Sendmail 8.12.6, 8.11.6-15, and possibly other versions after 8.11 fro
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Monkey HTTP Server 0.1/0.4/0.5 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in Monkey 0.5.0 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun ONE Starter Kit 2.0 / ASTAware SearchDisc 3.1 - Search Engine Directory Traversal
Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rogue 5.3 - Local Buffer Overflow
Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EmuMail 5.0 Email Form - Script Injection
Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EmuMail 5.0 - Web Root Full Path Disclosure
emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed st
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jetty 4.1 Servlet Engine - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SafeTP 1.46 - Passive Mode Internal IP Address Revealing
SafeTP 1.46, when network address translation (NAT) is being used, leaks the internal IP address of the FTP server in a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.