Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.542VulnCheck XDB 9091Nuclei 4434Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
AnalogX Proxy 4.0 - Socks4A Buffer Overflow
Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
E-Guest 1.1 - Server Side Include Arbitrary Command Execution
Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mandrake 7/8/9 / RedHat 6.x/7 Bonobo EFSTool - Commandline Argument Buffer Overflow (1)
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mandrake 7/8/9 / RedHat 6.x/7 Bonobo EFSTool - Commandline Argument Buffer Overflow (2)
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mandrake 7/8/9 / RedHat 6.x/7 Bonobo EFSTool - Commandline Argument Buffer Overflow (3)
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Macromedia JRun 3/4 - Administrative Authentication Bypass
Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra sl
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Summit Computer Networks Lil' HTTP Server 2 - 'URLCount.cgi' HTML Injection
Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WU-IMAP 2000.287(1-2) - Remote Overflow
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Inktomi Traffic Server 4/5 - Traffic_Manager Path Argument Buffer Overflow
Buffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Me
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH 3.x - Challenge-Response Buffer Overflow (2)
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large nu
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH 3.x - Challenge-Response Buffer Overflow (1)
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large nu
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.7 - 'ext.dll' Cross-Site Scripting
Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache mod_ssl 2.8.x - Off-by-One HTAccess Buffer Overflow
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apach
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YaBB 1 - Invalid Topic Error Page Cross-Site Scripting
Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pirch IRC 98 Client - Malformed Link Buffer Overrun
Buffer overflow in the Pirch 98 IRC client allows remote attackers to cause a denial of service and possibly execute arb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.x - 'rpc.xfsmd' Remote Command Execution
xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are no
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Half-Life Server 1.1/3.1 - New Player Flood Denial of Service
Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via mult
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BasiliX Webmail 1.1 - Message Content Script Injection
Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server 2000 / Microsoft Jet 4.0 Engine - Unicode Buffer Overflow (PoC)
Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco VPN Client for Unix 3.5.1 - Local Buffer Overflow
Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative priv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Interbase 6.0 - GDS_Drop Interbase Environment Variable Buffer Overflow (2)
Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase code
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Interbase 6.0 - GDS_Drop Interbase Environment Variable Buffer Overflow (2)
Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wolfram Research webMathematica 4.0 - File Disclosure
Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.x/2.0.x - Chunked-Encoding Memory Corruption (2)
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.x/2.0.x - Chunked-Encoding Memory Corruption (1)
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Address 0.2 e - Remote File Inclusion
globals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
osCommerce 2.1 - Remote File Inclusion
PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
osCommerce 2.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Interbase 6.0 - GDS_Drop Interbase Environment Variable Buffer Overflow (1)
Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
My Postcards 6.0 - 'MagicCard.cgi' Arbitrary File Disclosure
Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.