Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.542VulnCheck XDB 9091Nuclei 4434Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
AOL Instant Messenger 4.x - Unauthorized Actions
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3.3/4.0/4.2 MERCUR MailServer - Control-Service Buffer Overflow
Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IMHO Webmail 0.9x - Account Hijacking
The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Real Networks RealJukebox 1.0.2/RealOne 6.0.10 Player Gold - Skinfile Buffer Overflow
Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - SMTP Service Encapsulated SMTP Address (MS99-027)
The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-rel
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ultrafunk Popcorn 1.20 - Multiple Denial of Service Vulnerabilities
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t").
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun i-Runbook 2.5.2 - Directory and File Content Disclosure
none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argume
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Summit Computer Networks Lil' HTTP Server 2.1/2.2 - 'pbcgi.cgi' Cross-Site Scripting
Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun i-Runbook 2.5.2 - Directory and File Content Disclosure
Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 4.0.3 - Servlet Mapping Cross-Site Scripting
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users v
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Tru64 4.0/5.0/5.1 - _XKB_CHARSET Local Buffer Overflow
Buffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - OBJECT Tag Same Origin Policy Violation
Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which al
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.1.x - Error Page Cross-Site Scripting
Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web user
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fluid Dynamics Search Engine 2.0 - Cross-Site Scripting
Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.1.x - URL Encoded Slash Directory Traversal
Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL wi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
icecast server 1.3.12 - Directory Traversal Information Disclosure
Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iPlanet Web Server 4.1 - Search Component File Disclosure
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.7.3 - GET Denial of Service
BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.7.3 - 'cleanSearchString()' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Key Focus KF Web Server 1.0.2 - Directory Contents Disclosure
KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.1.x - SoftwareUpdate Arbitrary Package Installation
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Foundation Class Library 7.0 - ISAPI Buffer Overflow
Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Cl
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ArGoSoft 1.8 Mail Server - Directory Traversal
Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WorldSpan Res Manager 4.1 - Malformed TCP Packet Denial of Service
Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malf
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun SunPCi II VNC Software 2.3 - Password Disclosure
SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nullsoft Winamp 2.80 - Automatic Update Check Buffer Overflow
Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Tru64/OSF1 DXTerm - Local Buffer Overflow
Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpAuction 1/2 - Unauthorized Administrative Access
login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action param
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AnalogX Proxy 4.0 - Socks4A Buffer Overflow
Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BlackBoard 5.0 - Cross-Site Scripting
Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.