Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
AzDGDatingLite 2.1.1 - 'view.php?id' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kerio Personal Firewall 4.0.x - Web Filtering Remote Denial of Service
The Web Filtering functionality in Kerio Personal Firewall (KPF) 4.0.13 allows remote attackers to cause a denial of ser
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mcafee FreeScan CoMcFreeScan Browser - Object Buffer Overflow (PoC)
Mcafee FreeScan allows remote attackers to cause a denial of service and possibly arbitrary code via a long string in th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AzDGDatingLite 2.1.1 - 'index.php?language' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in AzDGDatingLite 2.1.1 allows remote attackers to inject arbitrary web script
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Security Check Virus Detection - COM Object Denial of Service
rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mcafee FreeScan CoMcFreeScan Browser - Information Disclosure
McFreeScan.CoMcFreeScan.1 ActiveX object in Mcafee FreeScan allows remote attackers to obtain sensitive information via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Blaxxun Contact 3D - X-CC3D Browser Object Buffer Overflow (PoC)
Buffer overflow in blaxxun 3D 7.0 allows remote attackers to execute arbitrary code via a long URL property inside an ob
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Panda ActiveScan 5.0 - 'ascontrol.dll' Remote Heap Overflow
Buffer overflow in ascontrol.dll in Panda ActiveScan 5.0 allows remote attackers to execute arbitrary code via the Inter
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
tcpdump - ISAKMP Identification Payload Integer Overflow
Integer underflow in the isakmp_id_print for TCPDUMP 3.8.1 and earlier allows remote attackers to cause a denial of serv
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ada imgsvr 0.4 - Directory Traversal
Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote attackers to read arbitrary files or li
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aborior Encore Web Forum - Arbitrary Command Execution
display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Vista - ARP Table Entries Denial of Service
Microsoft Windows XP and Vista overwrites ARP table entries included in gratuitous ARP, which allows remote attackers to
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ADA IMGSVR 0.4 - Remote Directory Listing
Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ADA IMGSVR 0.4 - Arbitrary File Download
Ada Image Server (ImgSvr) 0.4 allows remote attackers to view directories or download files via an HTTP request with a t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CactuSoft CactuShop 5.0/5.1 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in popuplargeimage.asp in CactuShop 5.x allows remote attackers to inject arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cactusoft CactuShop 5.0/5.1 - SQL Injection
SQL injection vulnerability in (1) mailorder.asp or (2) payonline.asp in CactuShop 5.x allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Roger Wilco Server 1.4.1 - Unauthorized Audio Stream Denial of Service
Roger Wilco 1.4.1.6 and earlier, or Roger Wilco Base Station 0.30a or earlier, allows remote attackers to send audio to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Roger Wilco Server 1.4.1 - UDP Datagram Handling Denial of Service
Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Interchange 4.8.x/5.0 - Remote Information Disclosure
Interchange before 5.0.1 allows remote attackers to "expose the content of arbitrary variables" and read or modify sensi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LinBit Technologies LINBOX Officeserver - Remote Authentication Bypass
LINBOX LIN:BOX allows remote attackers to bypass authentication, obtain sensitive information, or gain access via a dire
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MPlayer 0.9/1.0 - Remote HTTP Header Buffer Overflow
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute ar
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alan Ward A-CART 2.0 - 'category.asp?catcode' SQL Injection (2)
SQL injection vulnerability in category.asp in A-CART Pro and A-CART 2.0 allows remote attackers to gain privileges via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fresh Guest Book 1.0/2.x - HTML Injection
Cross-site scripting (XSS) vulnerability in guest.cgi in Fresh Guest Book allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PhotoPost PHP Pro 3.x/4.x - 'showgallery.php' Multiple SQL Injections
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' pass
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebCT Campus Edition 3.8/4.x - HTML Injection
Cross-site scripting (XSS) vulnerability in WebCT Campus Edition 4.1.1.5 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB
PhotoPost < 4.6 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' pass
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RealSecure / Blackice - 'iss_pam1.dll' Remote Overflow
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ethereal 0.10.0 < 0.10.2 - IGAP Overflow
Multiple buffer overflows in Ethereal 0.8.13 to 0.10.2 allow remote attackers to cause a denial of service and possibly
35RIESGO
abrir ↗Exploit-DB
PhotoPost < 4.6 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inj
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - ASN.1 Remote (MS04-007)
Multiple integer overflows in Microsoft ASN.1 library (MSASN1.DLL), as used in LSASS.EXE, CRYPT32.DLL, and other Microso
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.