Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Demarc PureSecure 1.0.5 - Authentication Check SQL Injection
Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Burning Board 1.1.1 - 'URL' Manipulation
Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.5/6.0 - History List Script Injection
The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Melange Chat System 2.0.2 Beta 2 - '/yell' Remote Buffer Overflow
Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (cras
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (2)
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SunShop Shopping Cart 1.5/2.x - User-Embedded Scripting
Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IRIX 6.5.x - Performance Co-Pilot Remote Denial of Service
Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ISC INN 2.0/2.1/2.2.x - Multiple Local Format String Vulnerabilities
Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 2.9/3.0 - Default Crontab Root Command Injection
mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Informix Web Datablade 4.1x - Page Request SQL Injection
webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary file
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - HTTP Error Page Cross-Site Scripting
Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to exec
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (1)
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (3)
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Abyss Web Server 1.0 - File Disclosure
Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Abyss Web Server 1.0 - File Disclosure
Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpGroupWare 0.9.13 - Debian Package Configuration
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to com
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Cascading Style Sheet File Disclosure (MS02-023)
Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" chara
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Solaris 2.6/7.0/8 - XSun Color Database File Heap Overflow
Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color databa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 8i - TNS Listener Local Command Parameter Buffer Overflow
Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SquirrelMail 1.2.x - Theme Remote Command Execution
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the TH
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PostNuke 0.703 - caselist Arbitrary Module Include
PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and po
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix NFuse 1.51/1.6 - Cross-Site Scripting
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LogWatch 2.1.1/2.5 - Insecure Temporary Directory Creation
LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary director
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CSSearch 2.3 - Remote Command Execution
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup comman
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x/2.3/2.4.x - 'd_path()' Path Truncation
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generat
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DCShop Beta 1.0 - Form Manipulation
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the data
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Progress Database 9.1 - sqlcpp Local Buffer Overflow
Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WorkforceROI Xpede 4.1/7.0 - Weak Password Encryption
Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Win32 1.3.x/2.0.x - Batch File Remote Command Execution
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 5.x - Error Message Web Root Disclosure
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.