Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.973GitHub PoC 15.478VulnCheck XDB 9069Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
OllyDbg 1.10 - Format String
Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly ex
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Mailutils 0.6 - Mail Email Header Buffer Overflow
Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions befo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
xine 0.99.2 - Remote Stack Overflow
Multiple stack-based buffer overflows in xine-lib 1-rc2 through 1-rc5 allow attackers to execute arbitrary code via (1)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU CFEngine 2.0.x/2.1 - AuthenticationDialogue Remote Heap Buffer Overrun (2)
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU CFEngine 2.0.x/2.1 - AuthenticationDialogue Remote Heap Buffer Overrun (1)
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RhinoSoft Serv-U FTP Server 3.x < 5.x - Local Privilege Escalation
Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users t
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pavuk Digest - Authentication Remote Buffer Overflow
Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attacke
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.3.7 - 'php-exec-dir' Patch Command Access Restriction Bypass
The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass rest
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Messenger (Linux) - Denial of Service (MS03-043)
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allow
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CVSTrac - Arbitrary Code Execution
filediff in CVStrac allows remote attackers to execute arbitrary commands via shell metacharacters in rcsinfo.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BlackJumboDog FTP Server - Remote Buffer Overflow
Buffer overflow in BlackJumboDog 3.x allows remote attackers to execute arbitrary code via long FTP commands such as (1)
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ethereal 0.x - Multiple iSNS / SMB / SNMP Protocol Dissector Vulnerabilities
The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abor
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SoX - '.wav' Local Buffer Overflow
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - 'mshtml.dll' Remote Null Pointer Crash
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (browser crash) via a link with
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Acme thttpd 2.0.7 - Directory Traversal
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free Web Chat Initial Release - Connection Saturation Denial of Service
Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenFTPd 0.30.1 - message system Remote Shell
Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free Web Chat Initial Release - UserManager.java Null Pointer Denial of Service
The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (unca
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eNdonesia 8.3 - Search Form Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in mod.php in eNdonesia 8.3 allow remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 9i - Multiple Vulnerabilities
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.26 - File Offset Pointer Handling Memory Disclosure
Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portio
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenFTPd 0.30.2 - Remote Overflow
Format string vulnerability in the msg command (cat_message function in msg.c) in OpenFTPD 0.30.2 and earlier allows rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Tivoli Directory Server 3.2.2/4.1 - LDACGI Directory Traversal
Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla 1.x / Netscape 7.0/7.1 - SOAP Integer Overflow
Integer overflow in the SOAPParameter object constructor in (1) Netscape version 7.0 and 7.1 and (2) Mozilla 1.6, and po
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Citadel/UX - Remote Denial of Service (PoC)
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Webcam Corp Webcam Watchdog 4.0.1 - 'sresult.exe' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in sresult.exe in Webcam Watchdog 4.0.1a allows remote attackers to inject arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache - Arbitrary Long HTTP Headers Denial of Service
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memor
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SoX - Local Buffer Overflow
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - Task Scheduler '.job' Universal (MS04-022)
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, al
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PowerPortal 1.1/1.3 - Private Message HTML Injection
Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attacker
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.