Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.269exploits catalogados
37.817CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.556VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
SonicWALL SOHO3 6.3 - Content Blocking Script Injection
Cross-site scripting (XSS) vulnerability in content blocking in SonicWALL SOHO3 6.3.0.0 allows remote attackers to injec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hosting Controller 1.4 - Import Root Directory Command Execution
imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hosting Controller 1.x - DSNManager Directory Traversal
Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary fil
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1/6.0 - Content-Disposition Handling File Execution
20RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1/6.0 - Content-Disposition Handling File Execution
Microsoft Internet Explorer 5.01 and 6.0 allow remote attackers to execute arbitrary code via malformed Content-Disposit
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 5.12/6.0 - Frame Location Same Origin Policy Circumvention
Opera 6.01, 6.0, and 5.12 allows remote attackers to execute arbitrary JavaScript in the security context of other sites
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
id Software Quake II Server 3.20/3.21 - Remote Information Disclosure
Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to obtain sensitive server cvar variables, obtain directory li
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.1 - Remote Command Execution
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which i
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NOCC 0.9.x - Webmail Script Injection
Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Squid 2.4.1 - Remote Buffer Overflow
Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Critical Path InJoin Directory Server 4.0 - File Disclosure
iCon administrative web server for Critical Path inJoin Directory Server 4.0 allows authenticated inJoin administrators
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (1)
Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Critical Path InJoin Directory Server 4.0 - Cross-Site Scripting
Cross-site scripting vulnerabilities in iCon administrative web server for Critical Path inJoin Directory Server 4.0 all
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WU-IMAPd 2000/2001 - Partial Mailbox Attribute Remote Buffer Overflow (2)
Buffer overflow in University of Washington imap server (uw-imapd) imap-2001 (imapd 2001.315) and imap-2001a (imapd 2001
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco ATA-186 - HTTP Device Configuration Disclosure
The web-based configuration interface for the Cisco ATA 186 Analog Telephone Adaptor allows remote attackers to bypass a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ISC DHCPD 2.0/3.0.1 - NSUPDATE Remote Format String
Format string vulnerabilities in the logging routines for dynamic DNS code (print.c) of ISC DHCP daemon (DHCPD) 3 to 3.0
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WorldClient 5.0.x - Arbitrary File Deletion
Directory traversal vulnerability in WorldClient.cgi in WorldClient for Alt-N Technologies MDaemon 5.0.5.0 and earlier a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MDaemon WorldClient 5.0.x - Folder Creation Buffer Overflow
Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
B2 0.6 - 'b2edit.showposts.php?b2inc' Remote File Inclusion
b2edit.showposts.php in B2 2.0.6pre2 and earlier does not properly load the b2config.php file in some configurations, wh
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
askSam 4.0 Web Publisher - Cross-Site Scripting
Cross-site scripting vulnerability (XSS) in (1) as_web.exe and (2) as_web4.exe in askSam Web Publisher 1 and 4 allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Outfront Spooky 2.x - Login SQL Query Manipulation Password
SQL injection vulnerability in Spooky Login 2.0 through 2.5 allows remote attackers to bypass authentication and gain pr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SSH (x2) - Remote Command Execution
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BEA Systems WebLogic Server and Express 7.0 - Null Character Denial of Service
BEA Systems Weblogic Server 6.1 allows remote attackers to cause a denial of service via a series of requests to .JSP fi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyGuestbook 1.0 - Script Injection
Cross-site scripting vulnerability in MyGuestbook 1.0 allows remote attackers to execute arbitrary script or inject HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Blahz-DNS 0.2 - Direct Script Call Authentication Bypass
Blahz-DNS 0.2 and earlier allows remote attackers to bypass authentication and modify configuration by directly requesti
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DNSTools 2.0 - Authentication Bypass
dnstools.php for DNSTools 2.0 beta 4 and earlier allows remote attackers to bypass authentication and gain privileges by
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ACME Labs thttpd 2.20 - Cross-Site Scripting
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHProjekt 2.x/3.x - Authentication Bypass
PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (4)
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 4.0/4.1 - Servlet Full Path Disclosure
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the in
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.