Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
DATEV Nutzungskontrolle 2.1/2.2 - Unauthorized Access
DATEV Nutzungskontrolle 2.1 and 2.2 has insecure write permissions for critical registry keys, which allows local users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BRS Webweaver 1.06 - HTTPd 'User-Agent' Remote Denial of Service
Buffer overflow in BRS WebWeaver 1.06 and earlier allows remote attackers to cause a denial of service (crash) and possi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Metaframe XP - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in login.asp in Citrix MetaFrame XP Server 1.0 allows remote attackers to injec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BEA WebLogic 6/7/8 - InteractiveQuery.jsp Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in InteractiveQuery.jsp for BEA WebLogic 8.1 and earlier allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MLdonkey 2.5-4 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Mldonkey 2.5-4 allows remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tritanium Scripts Tritanium Bulletin Board 1.2.3 - Unauthorized Access
index.php in Tritanium Bulletin Board 1.2.3 allows remote attackers to read and reply to arbitrary messages by modifying
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seyeon FlexWATCH Network Video Server 2.2 - Unauthorized Administrative Access
FlexWATCH Network video server 132 allows remote attackers to bypass authentication and gain administrative privileges v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BEA Tuxedo 6/7/8 and WebLogic Enterprise 4/5 - Input Validation
The Administration Console for BEA Tuxedo 8.1 and earlier allows remote attackers to determine the existence of files ou
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ledscripts LedForums - Multiple HTML Injections
Cross-site scripting (XSS) vulnerability in index.php for Ledscripts.com LedForums Beta 1 allows remote attackers to inj
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Serious Sam Engine 1.0.5 - Remote Denial of Service
Croteam Serious Sam demo test 2 2.1a, Serious Sam: the First Encounter 1.05, and Serious Sam: the Second Encounter 1.05
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
E107 - 'Chatbox.php' Denial of Service
chatbox.php in e107 0.554 and 0.603 allows remote attackers to cause a denial of service (pages fail to load) via HTML i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
kpopup 0.9.x - Privileged Command Execution
misc.cpp in KPopup 0.9.1 trusts the PATH variable when executing killall, which allows local users to elevate their priv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fastream NetFile 6.0.3.588 - Error Message Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Fastream NETFile Server 6.0.3.588 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Centrinity FirstClass HTTP Server 7.1 - Directory Disclosure
Centrinity FirstClass 7.1 allows remote attackers to access sensitive information by appending search to the end of the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chi Kien Uong Guestbook 1.51 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Chi Kien Uong Guestbook 1.51 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris Runtime Linker (SPARC) - 'ld.so.1' Local Buffer Overflow
Stack-based buffer overflow in the runtime linker, ld.so.1, on Solaris 2.6 through 9 allows local users to gain root pri
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Musicqueue 1.2 - SIGSEGV Signal Handler Insecure File Creation
Musicqueue 1.2.0 allows local users to overwrite arbitrary files by triggering a segmentation fault and using a symlink
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 5.6 - File Transfer Buffer Overrun
Buffer overflow in Yahoo! Messenger 5.6 allows remote attackers to cause a denial of service (crash) via a file send req
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireless Tools 26 (IWConfig) - ARGV Local Command Line Buffer Overflow (1)
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SH-HTTPD 0.3/0.4 - Character Filtering Remote Information Disclosure
Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a G
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
thttpd 2.2x - 'defang' Remote Buffer Overflow
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Apache 2.0.40 - Directory Index Default Configuration Error
The default configuration of Apache 2.0.40, as shipped with Red Hat Linux 9.0, allows remote attackers to list directory
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
thttpd 2.2x - 'defang' Remote Buffer Overflow (PoC)
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Musicqueue 0.9/1.0/1.1 - Multiple Buffer Overrun Vulnerabilities
Buffer overflow in Musicqueue 1.2.0 allows local users to execute arbitrary code via a long language variable in the con
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Norton Internet Security 2003 6.0.4.34 - Error Message Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Symantec Norton Internet Security 2003 6.0.4.34 allows remote attackers to i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireless Tools 26 (IWConfig) - ARGV Local Command Line Buffer Overflow (3)
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Les Visiteurs 2.0 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Microsystems Java Virtual Machine 1.x - Security Manager Denial of Service
Sun Java 1.3.1, 1.4.1, and 1.4.2 allows local users to cause a denial of service (JVM crash), possibly by calling the Cl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - Messenger Service Buffer Overrun (MS03-043)
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allow
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Macromedia Flash Player 6.0.x - Flash Cookie Predictable File Location
Macromedia Flash Player before 7,0,19,0 stores a Flash data file in a predictable location that is accessible to web bro
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.