Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.542VulnCheck XDB 9091Nuclei 4434Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
vBulletin 2.0.3 - 'calendar.php' Command Execution
calendar.php in vBulletin before 2.2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GV 2.x/3.x - '.PDF'/'.PS' File Buffer Overflow (1)
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GV 2.x/3.x - '.PDF'/'.PS' File Buffer Overflow (2)
Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DaCode 1.2 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in DaCode 1.2.0 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Monkey HTTP Server 0.1.4 - File Disclosure
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (do
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NPDS 4.8 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Interbase 5/6 - GDS_Lock_MGR UMask File Permission Changing
gds_lock_mgr in Borland InterBase allows local users to overwrite files and gain privileges via a symlink attack on a "i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.8.3 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in article.php module for phpWebSite 0.8.3 allows remote attackers to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenVms 5.3/6.2/7.x - UCX POP Server Arbitrary File Modification
The UCX POP server in HP TCP/IP services for OpenVMS 4.2 through 5.3 allows local users to truncate arbitrary files via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.0 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in PHP-Nuke 6.0 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 4.0 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ACWeb 1.14/1.8 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in acWEB 1.8 and 1.14 allows remote attackers to insert arbitrary HTML and web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XOOPS 1.0 RC3 - HTML Injection
Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.0.39/40 - Oversized STDERR Buffer Denial of Service
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 3/4 - 'DefaultServlet' File Disclosure
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Procurve 4000M Switch - Device Reset Denial of Service
The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.8.2 - PHP File Inclusion
modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP sour
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Compaq Insight Manager - Web Interface Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Null HTTPd 0.5 - Remote Heap Overflow
Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rudi Benkovic JAWMail 1.0 - Script Injection
Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.74 - IRC Raw Messages Denial of Service
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.74 - IRC Oversized Data Block Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.74 - IRC PART Message Denial of Service
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.725/0.73/0.74 - IRC User Mode Numeric Remote Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.2 - Terminal.APP Telnet Link Command Execution
Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.73/0.74 - IRC JOIN Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Word 95/97/98/2000/2002 - 'INCLUDEPICTURE' Document Sharing File Disclosure
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the i
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AlsaPlayer 0.99.71 - Local Buffer Overflow
Buffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a lo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft VM 2000/3000/3100/3188/3200/3300/3802/3805 series - JDBC Class Code Execution
Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote at
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.73/0.74 - IRC PRIVMSG Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.