Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8755Nuclei 4333Metasploit 3478✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
versatileBulletinBoard 1.00 RC2 - Board Takeover (SQL Injection)
Multiple SQL injection vulnerabilities in versatileBulletinBoard (vBB) 1.0.0 RC2 allow remote attackers to execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CA iTechnology iGateway - 'Debug Mode' Remote Buffer Overflow
Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows r
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.6.4-pl1 - Directory Traversal
PHP file inclusion vulnerability in grab_globals.lib.php in phpMyAdmin 2.6.4 and 2.6.4-pl1 allows remote attackers to in
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cyphor 0.19 - 'footer.php?t_login' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allows remote attackers to inject arbitrary web script or HTML v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cyphor 0.19 - 'newmsg.php?fid' SQL Injection
Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain adminis
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cyphor 0.19 - Board Takeover (SQL Injection)
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cyphor 0.19 - 'lostpwd.php?nick' SQL Injection
Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain adminis
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9.0 iSQL*Plus - TLS Listener Remote Denial of Service
iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Utopia News Pro 1.1.3 - 'header.php?sitetitle' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Utopia News Pro 1.1.3 - 'footer.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aenovo - '/Password/default.asp?Password' SQL Injection
Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle HTML DB 1.5/1.6 - 'wwv_flow.accept?p_t02' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9 - XML DB Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aenovo - '/incs/searchdisplay.asp?strSQL' SQL Injection
Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Forms - Servlet TLS Listener Remote Denial of Service
The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS liste
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle HTML DB 1.5/1.6 - 'f?p=' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Utopia News Pro 1.1.3 - 'news.php' SQL Injection
SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TellMe 1.2 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in TellMe 1.2 and earlier allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 1.0.6/1.0.7 - iFrame Handling Denial of Service
Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IF
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - Wireless Zero Configuration Service Information Disclosure
The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Gnome-PTY-Helper UTMP - Hostname Spoofing
gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY envi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Virtools Web Player 3.0.0.100 - Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a lon
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Prozilla 1.3.7.4 - 'ftpsearch' Results Handling Buffer Overflow
Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IceWarp Web Mail 5.5.1 - 'calendar_d.html?createdataCX' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IceWarp Web Mail 5.5.1 - 'blank.html?id' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Merak Mail Server 8.2.4 r - Arbitrary File Deletion
Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IceWarp Web Mail 5.5.1 - 'calendar_m.html?createdataCX' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IceWarp Web Mail 5.5.1 - 'calendar_w.html?createdataCX' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SquirrelMail 1.4.2 Address Add Plugin - 'add.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote att
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LucidCMS 2.0 - Login SQL Injection
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login f
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.