Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - Self-Referential Object Denial of Service
Microsoft Internet Explorer 5.0 through 6.0 allows remote attackers to cause a denial of service (crash) via an object o
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PostBoard 2.0 - Topic Title Script Execution
Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other u
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Snitz Forums 2000 3.x - 'members.asp' SQL Injection
members.asp in Snitz Forums 2000 version 3.3.03 and earlier allows remote attackers to execute arbitrary code via a SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
National Instruments LabVIEW 5.1.1/6.0/6.1 - HTTP Request Denial of Service
LabVIEW Web Server 5.1.1 through 6.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET reques
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH 2.x/3.x - Kerberos 4 TGT/AFS Token Buffer Overflow
Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IcrediBB 1.1 - Script Injection
Cross-site scripting (CSS) vulnerability in IcrediBB 1.1 Beta allows remote attackers to execute arbitrary script and st
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PostBoard 2.0 - BBCode IMG Tag Script Injection
Cross-site scripting vulnerabilities in PostBoard 2.0.1 and earlier allows remote attackers to execute script as other u
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PVote 1.0/1.5 - Unauthorized Administrative Password Change
PVote before 1.9 allows remote attackers to change the administrative password and gain privileges by directly calling c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PVote 1.0/1.5 - Poll Content Manipulation
PVote before 1.9 does not authenticate users for restricted operations, which allows remote attackers to add or delete p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SSH2 3.0 - Restricted Shell Escape (Command Execution)
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by up
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sambar Server 5.1 - Script Source Disclosure
Sambar web server before 5.2 beta 1 allows remote attackers to obtain source code of server-side scripts, or cause a den
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AOL Instant Messenger 4.x - Arbitrary File Creation
Directory traversal vulnerability in AOL Instant Messenger (AIM) 4.8 beta and earlier allows remote attackers to create
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebTrends Reporting Center for Windows 4.0 d - GET Buffer Overflow
Buffer overflow in WTRS_UI.EXE (WTX_REMOTE.DLL) for WebTrends Reporting Center 4.0d allows remote attackers to execute a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Lanman Denial of Service (1)
LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) vi
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ecometry SGDynamo 5.32/6.1/7.0 - Cross-Site Scripting
Cross-site scripting vulnerability in sgdynamo.exe for Sgdynamo allows remote attackers to execute arbitrary Javascript
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FileSeek - CGI Script File Disclosure
Directory traversal vulnerability in FileSeek.cgi allows remote attackers to read arbitrary files via a ....// (modified
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Dialog Same Origin Policy Bypass Variant (MS02-047)
Cross-site scripting vulnerability in Internet Explorer 6.0 allows remote attackers to execute scripts in the Local Comp
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FileSeek CGI Script - Remote Command Execution
FileSeek.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) head or (2) foot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - 'CodeBrws.asp' Source Code Disclosure
Directory traversal vulnerability in CodeBrws.asp in Microsoft IIS 5.0 allows remote attackers to view source code and d
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Demarc PureSecure 1.0.5 - Authentication Check SQL Injection
Demarc PureSecure 1.05 allows remote attackers to gain administrative privileges via a SQL injection attack in a session
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.5/6.0 - History List Script Injection
The browser history feature in Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to execute arbitrary
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nortel CVX 1800 Multi-Service Access Switch - Default SNMP Community
Nortel CVX 1800 is installed with a default "public" community string, which allows remote attackers to read usernames a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Burning Board 1.1.1 - 'URL' Manipulation
Cross-site scripting (XSS) vulnerability in WoltLab Burning Board (wbboard) 1.1.1 allows remote attackers to inject arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3CDaemon 2.0 - Buffer Overflow (1)
Buffer overflow in 3Cdaemon 2.0 FTP server allows remote attackers to cause a denial of service (crash) and possibly exe
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Melange Chat System 2.0.2 Beta 2 - '/yell' Remote Buffer Overflow
Multiple buffer overflows in Melange Chat server 2.02 allow remote or local attackers to cause a denial of service (cras
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (2)
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SunShop Shopping Cart 1.5/2.x - User-Embedded Scripting
Cross-site scripting vulnerability in SunShop 2.5 and earlier allows remote attackers to gain administrative privileges
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IRIX 6.5.x - Performance Co-Pilot Remote Denial of Service
Performance Metrics Collector Daemon (PMCD) in Performance Copilot in IRIX 6.x allows remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Informix Web Datablade 4.1x - Page Request SQL Injection
webdriver in IBM Informix Web DataBlade 4.12 allows remote attackers to bypass user access levels or read arbitrary file
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 2.9/3.0 - Default Crontab Root Command Injection
mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode,
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.