Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
CGIScript.net - csMailto Hidden Form Field Remote Command Execution
CGIscript.net csMailto.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the form-at
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.x / FreeBSD 4.x / OpenBSD 2.x / Solaris 2.5/2.6/7.0/8 - 'exec C Library' Standard I/O File Descriptor Closure
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from res
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Matu FTP 1.74 - Client Buffer Overflow
Buffer overflow in Matu FTP client 1.74 allows remote FTP servers to execute arbitrary code via a long "220" banner.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Screen 3.9.x Braille Module - Local Buffer Overflow
Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
psyBNC 2.3 - Oversized Passwords Denial of Service
psyBNC 2.3 allows remote attackers to cause a denial of service (CPU consumption and resource exhaustion) by sending a P
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SLRNPull 0.9.6 - Spool Directory Command Line Parameter Buffer Overflow
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vqServer 1.9.x - CGI Demo Program Script Injection
Cross-site scripting vulnerability in demonstration scripts for vqServer allows remote attackers to execute arbitrary sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Philip Chinery's Guestbook 1.1 - Script Injection
Cross-site scripting vulnerability in guestbook.pl for Philip Chinery's Guestbook 1.1 allows remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - Self-Referential Object Denial of Service
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object o
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jon Howell Faq-O-Matic 2.7 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the fom CGI program (fom.cgi) in Faq-O-Matic 2.711 and 2.712 allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
National Instruments LabVIEW 5.1.1/6.0/6.1 - HTTP Request Denial of Service
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET reques
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IcrediBB 1.1 - Script Injection
Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and st
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Snitz Forums 2000 3.x - 'members.asp' SQL Injection
members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PostBoard 2.0 - Topic Title Script Execution
Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other u
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH 2.x/3.x - Kerberos 4 TGT/AFS Token Buffer Overflow
Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PostBoard 2.0 - BBCode IMG Tag Script Injection
Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other u
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PVote 1.0/1.5 - Unauthorized Administrative Password Change
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SSH2 3.0 - Restricted Shell Escape (Command Execution)
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by up
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PVote 1.0/1.5 - Poll Content Manipulation
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Lanman Denial of Service (1)
LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) vi
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sambar Server 5.1 - Script Source Disclosure
Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a den
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ecometry SGDynamo 5.32/6.1/7.0 - Cross-Site Scripting
Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebTrends Reporting Center for Windows 4.0 d - GET Buffer Overflow
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AOL Instant Messenger 4.x - Arbitrary File Creation
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FileSeek CGI Script - Remote Command Execution
FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FileSeek - CGI Script File Disclosure
Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - 'CodeBrws.asp' Source Code Disclosure
Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and d
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Dialog Same Origin Policy Bypass Variant (MS02-047)
Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Comp
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nortel CVX 1800 Multi-Service Access Switch - Default SNMP Community
Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3CDaemon 2.0 - Buffer Overflow (1)
Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly exe
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.