Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
NPDS 4.8 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 4.0 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.0.39/40 - Oversized STDERR Buffer Denial of Service
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 3/4 - 'DefaultServlet' File Disclosure
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XOOPS 1.0 RC3 - HTML Injection
Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Procurve 4000M Switch - Device Reset Denial of Service
The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rudi Benkovic JAWMail 1.0 - Script Injection
Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Null HTTPd 0.5 - Remote Heap Overflow
Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.8.2 - PHP File Inclusion
modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP sour
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Compaq Insight Manager - Web Interface Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.74 - IRC Oversized Data Block Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.74 - IRC PART Message Denial of Service
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.74 - IRC Raw Messages Denial of Service
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.2 - Terminal.APP Telnet Link Command Execution
Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.725/0.73/0.74 - IRC User Mode Numeric Remote Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.73/0.74 - IRC JOIN Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Word 95/97/98/2000/2002 - 'INCLUDEPICTURE' Document Sharing File Disclosure
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the i
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AlsaPlayer 0.99.71 - Local Buffer Overflow
Buffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a lo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft VM 2000/3000/3100/3188/3200/3300/3802/3805 series - JDBC Class Code Execution
Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote at
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.73/0.74 - IRC PRIVMSG Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SquirrelMail 1.2.6/1.2.7 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as othe
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.6351/0.7x - Identd Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco VPN 5000 Client - Buffer Overrun (1)
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco VPN 5000 Client - Buffer Overrun (2)
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DB4Web 3.4/3.6 - File Disclosure
db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP requ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DB4Web 3.4/3.6 - Connection Proxy
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attem
28RIESGO
abrir ↗Exploit-DB
Apache mod_ssl OpenSSL < 0.9.6d / < 0.9.7-beta2 - 'openssl-too-open.c' SSL2 KEY_ARG Overflow
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lycos HTMLGear - guestGear CSS HTML Injection
Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TCP SYN - 'bang.c' Denial of Service
Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WMNet2 1.0 6 - Kernel Memory File Descriptor Leakage
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblem
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.