Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
Ultimate Bulletin Board 5.4/6.0/6.2 - Cross-Agent Scripting
Cross-site scripting vulnerability in Infopop Ultimate Bulletin Board (UBB) 6.2.0 Beta Release 1.0 allows remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cacheflow CacheOS 3.1/4.0 Web Administration - Arbitrary Cached Page Code Leakage
Web administration interface in CacheFlow CacheOS 4.0.13 and earlier allows remote attackers to obtain sensitive informa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Boozt 0.9.8 - Remote Buffer Overflow
Buffer overflow in index.cgi administration interface for Boozt! Standard 0.9.8 allows local users to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke AddOn PHPToNuke.php 1.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in phptonuke.php for PHP-Nuke allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RealPlayer 7.0/8.0 - Media File Buffer Overflow
Buffer overflow in Real Networks RealPlayer 8.0 and earlier allows remote attackers to execute arbitrary code via a head
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BrowseFTP Client 1.62 - Remote Buffer Overflow
Buffer overflow in BrowseFTP 1.62 client allows remote FTP servers to execute arbitrary code via a long FTP "220" messag
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3.20 (Win32) - 'PHP.exe' Remote File Disclosure
PHP, when installed on Windows with Apache and ScriptAlias for /php/ set to c:/php/, allows remote attackers to read arb
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - JavaScript Local File Enumeration (2)
Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existenc
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - JavaScript Local File Enumeration (1)
Internet Explorer 5.0, 5.0.1 and 5.5 with JavaScript execution enabled allows remote attackers to determine the existenc
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Net-SNMP 4.2.3 - snmpnetstat Remote Heap Overflow
Heap-based buffer overflow in snmpnetstat for ucd-snmp 4.2.3 and earlier, and net-snmp, allows remote attackers to execu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BSCW 3.4/4.0 - Insecure Default Installation
The default configuration of BSCW (Basic Support for Cooperative Work) 3.x and possibly version 4 enables user self regi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WikkiTikkiTavi 0.x - Remote File Inclusion
PHP remote file inclusion vulnerability in WikkiTikkiTavi before 0.21 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AOL Instant Messenger 4.x - Remote Buffer Overflow
Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2/7/8/9 cachefsd - Remote Heap Overflow
Heap-based buffer overflow in cfsd_calloc function of Solaris cachefsd allows remote attackers to execute arbitrary code
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
rsync 2.5.1 - Remote (2)
Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other ver
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD - 'ftp' Local Overflow
FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings tha
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
rsync 2.5.1 - Remote (1)
Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other ver
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - GetObject File Disclosure
Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to read arbitrary files via malformed requests to the GetObj
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Abe Timmerman - 'zml.cgi' File Disclosure
Directory traversal vulnerability in zml.cgi allows remote attackers to read arbitrary files via a .. (dot dot) in the f
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DeleGate 7.7.1 - Cross-Site Scripting
Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
STunnel 3.x - Client Negotiation Protocol Format String
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris /bin/login (SPARC/x86) - Remote Code Execution
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alteon AceDirector - Half-Closed HTTP Request IP Address Revealing
Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 98/XP/ME - UPnP NOTIFY Buffer Overflow (2)
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arb
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 98/XP/ME - UPnP NOTIFY Buffer Overflow (1)
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arb
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QPopper 4.0.x - PopAuth Trace File Shell Command Execution
popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZYXEL Prestige 681 SDSL Router - IP Fragment Reassembly
Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aktivate 1.0 3 - Shopping Cart Cross-Site Scripting
Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascrip
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Agora.CGI 3.x/4.0 - Debug Mode Cross-Site Scripting
Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
webmin 0.91 - Directory Traversal
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.