Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8773Nuclei 4340Metasploit 3485✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.4 - launchd Race Condition
launchd 106 in Apple Mac OS X 10.4.x up to 10.4.1 allows local users to overwrite arbitrary files via a symlink attack o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Singapore 0.9.11 Beta Image Gallery - 'index.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.11 allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JamMail 1.8 - Jammail.pl Arbitrary Command Execution
jammail.pl in jamchen JamMail 1.8 allows remote attackers to execute arbitrary commands via shell metacharacters in the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Webhints 1.03 - Remote Command Execution (Perl) (3)
hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Webhints 1.03 - Remote Command Execution (C) (2)
hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Webhints 1.03 - Remote Command Execution (Perl) (1)
hints.pl in Webhints 1.03 allows remote attackers to execute arbitrary commands via shell metacharacters in the argument
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tcpdump - bgp_update_print Remote Denial of Service
The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Invision Power Services Invision Gallery 1.0.1/1.3 - SQL Injection
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Loki Download Manager 2.0 - 'Catinfo.asp' SQL Injection
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Loki Download Manager 2.0 - 'default.asp' SQL Injection
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FlatNuke 2.5.x - 'help.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.3 allows remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IPSwitch IMAP Server - LOGON Remote Stack Overflow
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), a
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kaspersky AntiVirus - 'klif.sys' Local Privilege Escalation
The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gai
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoodTech SMTP Server 5.14 - Denial of Service
GoodTech SMTP Server 5.14 allows remote attackers to cause a denial of service (application crash) via a RCPT TO command
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FlatNuke 2.5.x - 'index.php?where' Full Path Disclosure
FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FlatNuke 2.5.x - 'referer.php' Crafted Referer Arbitrary PHP Code Execution
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WinZip 8.1 - Command Line Local Buffer Overflow
Multiple buffer overflows in WinZip 9.0 and earlier may allow attackers to execute arbitrary code via multiple vectors,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rakkarsoft RakNet 2.33 - Remote Denial of Service
Rakkarsoft RakNet network library 2.33 and earlier, when released before 30 May 2005, and as used in multiple products i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YaPiG 0.9x - 'view.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Early Impact ProductCart 2.6/2.7 - 'viewPrd.asp?idcategory' SQL Injection
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Early Impact ProductCart 2.6/2.7 - 'modCustomCardPaymentOpt.asp?idc' SQL Injection
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YaPiG 0.9x - 'upload.php' Directory Traversal
Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portail PHP < 1.3 - SQL Injection
SQL injection vulnerability in PortailPHP 1.3 allows remote attackers to execute arbitrary SQL commands via the id param
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Early Impact ProductCart 2.6/2.7 - 'OptionFieldsEdit.asp?idccr' SQL Injection
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Early Impact ProductCart 2.6/2.7 - 'editCategories.asp?lid' SQL Injection
Multiple SQL injection vulnerabilities in ProductCart Ecommerce before 2.7 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YaPiG 0.9x - Local/Remote File Inclusion
upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FUSE 2.2/2.3 - Local Information Disclosure
FUSE 2.x before 2.3.0 does not properly clear previously used memory from unfilled pages when the filesystem returns a s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PostNuke 0.750 - 'readpmsg.php' SQL Injection
SQL injection vulnerability in readpmsg.php in PostNuke 0.750 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Popper Webmail 1.41 - 'ChildWindow.Inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in childwindow.inc.php in Popper 1.41-r2 and earlier allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Crob FTP Server 3.6.1 - Remote Stack Overflow
Multiple buffer overflows in Crob FTP 3.6.1, and possibly earlier versions, allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.