Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Webmin 0.x - Code Input Validation
The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the inter
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 / Mozilla 0.8/0.9.x / Opera 5/6 - JavaScript Interpreter Denial of Service
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 3.0.x/4.x - Move_Uploaded_File open_basedir Circumvention
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Qualcomm QPopper 4.0.x - Remote Denial of Service
Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumpti
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHProjekt 3.1 - Remote File Inclusion
filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/2000 - Process Handle Local Privilege Escalation
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to othe
71RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Interscan VirusWall 3.5/3.6 - Content-Length Scan Bypass
Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 7.0/8 Sunsolve CD - SSCD_SunCourier.pl CGI Script Arbitrary Command Execution
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shel
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XTux Server 2001.0 6.01 - Garbage Denial of Service
XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Menasoft SPHEREserver 0.99 - Denial of Service
Menasoft SPHERE server 0.99x and 0.5x allows remote attackers to cause a denial of service by establishing a large numbe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt RaQ 2.0/3.0/4.0 XTR - 'MultiFileUpload.php' Authentication Bypass (1)
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authenticatio
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt RaQ 2.0/3.0/4.0 XTR - 'MultiFileUpload.php' Authentication Bypass (2)
MultiFileUploadHandler.php in the Sun Cobalt RaQ XTR administration interface allows local users to bypass authenticatio
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xerver 2.10 - Multiple Request Denial of Service Vulnerabilities
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH 2.x/3.0.1/3.0.2 - Channel Code Off-by-One
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0/5.1 - Authentication Method Disclosure
Information leaks in IIS 4 through 5.1 allow remote attackers to obtain potentially sensitive information or more easily
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ReBB 1.0 - Image Tag Cross-Agent Scripting
Cross-site scripting vulnerability in ReBB allows remote attackers to execute arbitrary Javascript and steal cookies via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Galacticomm Worldgroup 3.20 - Remote Web Server Denial of Service
Buffer overflow in Galacticomm Worldgroup web server 3.20 and earlier allows remote attackers to cause a denial of servi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BPM Studio Pro 4.2 - HTTPd Directory Traversal
Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote attackers to read arbitrary fi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rit Research Labs The Bat! 1.53 - Microsoft Denial of Service Device Name Denial of Service
The Bat! 1.53d and 1.54beta, and possibly other versions, allows remote attackers to cause a denial of service (crash) v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
xtell 2.6.1 - User Status Remote Information Disclosure
Directory traversal vulnerability in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
xtell 1.91.1/2.6.1 - Multiple Remote Buffer Overflow Vulnerabilities
Buffer overflows in xtell (xtelld) 1.91.1 and earlier, and 2.x before 2.7, allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ecartis 1.0.0/0.129 a Listar - Multiple Local Buffer Overflow Vulnerabilities (1)
Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privilege
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ecartis 1.0.0/0.129 a Listar - Multiple Local Buffer Overflow Vulnerabilities (2)
Buffer overflows in Ecartis (formerly Listar) 1.0.0 in snapshot 20020427 and earlier allow local users to gain privilege
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Snitz Forums 2000 3.0/3.1/3.3 - Image Tag Cross-Agent Scripting
Cross-site scripting vulnerability in Snitz Forums 2000 3.3.03 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Galacticomm Worldgroup 3.20 - Remote FTP Denial of Service
Buffer overflow in Galacticomm Worldgroup FTP server 3.20 and earlier allows remote attackers to cause a denial of servi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IkonBoard 2.17/3.0/3.1 - Image Tag Cross-Agent Scripting
Cross-site scripting vulnerability in Ikonboard 3.0.1 allows remote attackers to execute arbitrary script as other Ikonb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.5/1.6 - Directory Traversal
Directory traversal vulnerability in BadBlue before 1.6.1 allows remote attackers to read arbitrary files via a ... (mod
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBB 1.0.x - Image Tag Cross-Agent Scripting
Cross-site scripting vulnerability in codeparse.php of Open Bulletin Board (OpenBB) 1.0.0 allows remote attackers to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Century Software Term For Linux 6.27.869 - Command Line Buffer Overflow
Buffer overflow in Century Software TERM allows local users to gain root privileges via a long tty argument to the calli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XMB Forum 1.6 pre-beta - Image Tag Script Injection
Cross-site scripting vulnerability in eXtreme message board (XMB) 1.6x and earlier allows remote attackers to execute sc
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.