Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8755Nuclei 4333Metasploit 3478✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
MySource 2.14 - 'insert_table.php?bgcolor' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'mail.php?PEAR_PATH' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'Date.php?PEAR_PATH' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'upgrade_in_progress_backend.php?target_url' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Snort 2.4.0 < 2.4.3 - Back Orifice Pre-Preprocessor Remote (Metasploit)
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetFlow Analyzer 4 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.jsp in ManageEngine Netflow Analyzer 4.0.2 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'mime.php?PEAR_PATH' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'mimeDecode.php?PEAR_PATH' Remote File Inclusion
Multiple PHP file inclusion vulnerabilities in MySource 2.14.0 allow remote attackers to execute arbitrary PHP code and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'edit_table_cell_type_wysiwyg.php?Stylesheet' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySource 2.14 - 'edit_table_row_props.php?bgcolor' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MySource 2.14.0 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.6 - Console Keymap Local Command Injection
The VT implementation (vt_ioctl.c) in Linux kernel 2.6.12, and possibly other versions including 2.6.14.4, allows local
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lynx 2.8.6dev.13 - Remote Buffer Overflow (PoC)
Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbit
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Comersus Backoffice Plus - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in comersus_backoffice_searchItemForm.asp in Comersus BackOffice Plus allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 8.02 - Remote Denial of Service (1)
Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file w
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 8.02 - Remote Denial of Service (2)
Opera 8.02 and earlier allows remote attackers to cause a denial of service (client crash) via (1) a crafted HTML file w
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PunBB 1.2.x - 'search.php' SQL Injection
SQL injection vulnerability in search.php in PunBB 1.2.7 and 1.2.8 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.11 - 'RETR' Denial of Service
TYPSoft FTP 0.95 allows remote attackers to cause a denial of service (CPU consumption) via a "../../*" argument to (1)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 4.0.3 - Requests Containing MS-DOS Device Names Information Disclosure
Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TYPSoft FTP Server 1.11 - 'RETR' Denial of Service
Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (cra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Complete PHP Counter - SQL Injection
Multiple SQL injection vulnerabilities in list.php in Complete PHP Counter allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Complete PHP - Counter Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in list.php in Complete PHP Counter allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YaPiG 0.95b - 'view.php?img_size' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Accelerated Mortgage Manager - 'Password' SQL Injection
SQL injection vulnerability in Accelerated Mortgage Manager allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebGUI 6.x - Arbitrary Command Execution
Unspecified vulnerability in the www_add method in Asset.pm in Plain Black WebGUI 6.3.0 and other versions before 6.7.6
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RARLAB WinRar 2.90/3.x - UUE/XXE Invalid Filename Error Message Format String
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via for
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Accelerated E Solutions - SQL Injection
SQL injection vulnerability in an unspecified Accelerated Enterprise Solutions product, possibly Accelerated E Solutions
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/2003 - MSDTC TIP Denial of Service (MS05-051)
Distributed Transaction Controller in Microsoft Windows allows remote servers to cause a denial of service (MSDTC servic
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xine-Lib 1.1 - 'Media Player Library' Remote Format String
Format string vulnerability in input_cdda.c in xine-lib 1-beta through 1-beta 3, 1-rc, 1.0 through 1.0.2, and 1.1.1 allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Up-IMAPProxy 1.2.3/1.2.4 - Multiple Unspecified Remote Format String Vulnerabilities
Format string vulnerability in the ParseBannerAndCapability function in main.c for up-imapproxy 1.2.3 and 1.2.4 allows r
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA iTechnology iGateway - 'Debug Mode' Remote Buffer Overflow
Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows r
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.