Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.056exploits catalogados
37.663CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.516VulnCheck XDB 9077Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Cisco IOS - using hping Remote Denial of Service
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a p
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - RPC DCOM Interface Denial of Service
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote attackers to cause a denial of service (crash), and loc
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS - 'cisco-bug-44020.c' IPv4 Packet Denial of Service
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a p
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS - IPv4 Packets Denial of Service
Cisco IOS 11.x and 12.0 through 12.2 allows remote attackers to cause a denial of service (traffic block) by sending a p
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XPCD 2.0.8 - 'HOME Environment' Local Buffer Overflow
Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME envi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Witango Server 5.0.1.061 - Remote Cookie Buffer Overflow
Buffer overflow in WiTango Application Server and Tango 2000 allows remote attackers to execute arbitrary code via a lon
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eStore 1.0.1/1.0.2 - 'Settings.inc.php' Full Path Disclosure
Brooky eStore 1.0.1 through 1.0.2b allows remote attackers to obtain sensitive path information via a direct HTTP reques
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tolis Group BRU 17.0 - Local Privilege Escalation (2)
Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM UniVerse 10.0.0.9 - 'uvadmsh' Local Privilege Escalation
uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tolis Group BRU 17.0 - Local Privilege Escalation (1)
Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft ISA Server 2000 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.3.x - Undefined Safe_Mode_Include_Dir Safemode Bypass
The php_check_safe_mode_include_dir function in fopen_wrappers.c of PHP 4.3.x returns a success value (0) when the safe_
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Splatt Forum 3/4 - Post Icon HTML Injection
Cross-site scripting (XSS) vulnerability in Splatt Forum allows remote attackers to insert arbitrary HTML and web script
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Media Services - 'nsiislog.dll' Remote Overflow
The logging capability for unicast and multicast transmissions in the ISAPI extension for Microsoft Windows Media Servic
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 2.2.8 - Brute Force Method Remote Command Execution
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LeapWare LeapFTP 2.7.x - Remote Buffer Overflow
Buffer overflow in LeapFTP 2.7.3.600 allows remote FTP servers to execute arbitrary code via a long IP address response
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
University of Minnesota Gopherd 2.0.x/2.3/3.0.x - FTP Gateway Buffer Overflow
Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
University of Minnesota Gopherd 2.0.x/2.3/3.0.x - GSisText Buffer Overflow
Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IglooFTP 0.6.1 - Banner Parsing Buffer Overflow
Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP bann
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Virtual Programming VP-ASP 5.00 - 'shopexd.asp' SQL Injection (1)
SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Virtual Programming VP-ASP 5.00 - 'shopexd.asp' SQL Injection (2)
SQL injection vulnerability in shopexd.asp for VP-ASP allows remote attackers to gain administrator privileges via the i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - CreateFile API Named Pipe Privilege Escalation (2)
Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - CreateFile API Named Pipe Privilege Escalation (1)
Microsoft SQL Server before Windows 2000 SP4 allows local users to gain privileges as the SQL Server user by calling the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - WebDAV Remote Code Execution (3) (xwdav)
Buffer overflow in ntdll.dll on Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Wind
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IglooFTP PRO 3.8 - Multiple Buffer Overflow Vulnerabilities (2)
Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP bann
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Twilight WebServer 1.3.3.0 - 'GET' Remote Denial of Service
Twilight Webserver 1.3.3.0 allows remote attackers to cause a denial of service (application crash) via a GET request fo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CPanel 5.0/5.3/6.x - Admin Interface HTML Injection
Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly g
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IglooFTP PRO 3.8 - Multiple Buffer Overflow Vulnerabilities (1)
Multiple buffer overflows in IglooFTP PRO 3.8 allow remote FTP servers to execute arbitrary code via (1) a long FTP bann
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProductCart 1.5/1.6/2.0 - File Disclosure
EarlyImpact ProductCart 1.0 through 2.0 stores database/EIPC.mdb under the web root with insufficient access control, wh
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProductCart 1.5/1.6/2.0 - 'MSG.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in msg.asp for certain versions of ProductCart allow remote attackers to execut
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.