Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8773Nuclei 4340Metasploit 3485✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
ProjectBB 0.4.5.1 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in ProjectBB 0.4.5.1 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian Basic 3.0 - '.png' Image Processing Buffer Overflow
Buffer overflow in Trillian 3.0 and Pro 3.0 allows remote attackers to execute arbitrary code via a crafted PNG image fi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPNews 1.2.3/1.2.4 - 'auth.php' Remote File Inclusion
PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
427BB 2.x - Multiple Remote HTML Injection Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in profile.php in 427BB 2.2 allow remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPCOIN 1.2 - 'mod.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPCOIN 1.2 - 'login.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpCOIN 1.2.0 through 1.2.1b allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Scrapland 1.0 - Server Termination Denial of Service
Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an err
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Einstein 1.01 - Local Password Disclosure (ASM)
Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BadBlue 2.5 - Easy File Sharing Remote Buffer Overflow
Buffer overflow in ext.dll in BadBlue 2.55 allows remote attackers to execute arbitrary code via a long mfcisapicommand
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eXeem 0.21 - Local Password Disclosure (ASM)
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local use
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KNet Web Server 1.04c - Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in Stormy Studios Knet 1.04c and earlier allows remote attackers to cause a denial of service and possib
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.6.2 - File Globbing Denial of Service
The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CubeCart 2.0.x - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in settings.inc.php for CubeCart 2.0.0 through 2.0.5, as used in multiple PHP f
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.6 - 'select_server.lib.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Soldier of Fortune 2 1.03 - 'cl_guid' Server Crash
Soldier of Fortune II 1.03 gold allows remote attackers to cause a denial of service (application crash) via a large cl_
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Avaya IP Office Phone Manager - Local Password Disclosure
The Avaya IP Office Phone Manager, and other products such as the IP Softphone, stores sensitive data in cleartext in a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PunBB 3.0/3.1 - Multiple Remote Input Validation Vulnerabilities
Multiple SQL injection vulnerabilities in PunBB 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.6 - 'display_tbl_links.lib.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.6 - 'theme_right.css.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.6 - 'theme_left.css.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.6.1 allows remote attackers to inject arbitrary HTML and web sc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
webconnect 6.4.4 < 6.5 - Directory Traversal / Denial of Service
Directory traversal vulnerability in jretest.html in WebConnect 6.5 and 6.4.4, and possibly earlier versions, allows rem
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Winace UnAce 1.x - ACE Archive Directory Traversal
Multiple directory traversal vulnerabilities in unace 1.2b allow attackers to overwrite arbitrary files via an ACE archi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chat Anywhere 2.72a - Local Password Disclosure
Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SendLink 1.5 - Local Password Disclosure
SendLink 1.5 stores sensitive information, possibly including passwords, in plaintext in the data.eat file, which allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0.6 - PHP Code Injection
misc.php for vBulletin 3.0.6 and earlier, when "Add Template Name in HTML Comments" is enabled, allows remote attackers
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PeerFTP 5 - Local Password Disclosure
PeerFTP_5 stores sensitive information such as passwords in plaintext in the PeerFTP.ini files, which allows local users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eXeem 0.21 - Local Password Disclosure
eXeem 0.21 stores sensitive information such as passwords in plaintext in the Exeem registry key, which allows local use
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Invision Power Board (IP.Board) 1.x/2.0.3 - SML Code Script Injection
Cross-site scripting (XSS) vulnerability in the SML code for Invision Power Board 1.3.1 FINAL allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SHOUTcast 1.9.4 (Windows) - File Request Format String Remote Overflow
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash)
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PMachine Pro 2.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in mail_autocheck.php in the Email This Entry add-on for pMachine Pro 2.4, and p
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.