Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
3D-FTP Client 4.0 - Buffer Overflow
Buffer overflow in 3D-FTP client 4.0 allows remote FTP servers to cause a denial of service (crash) and possibly execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 6.0.x/7.0 - Long File Name Remote Heap Corruption
Heap-based buffer overflow in Opera 6.05 through 7.10 allows remote attackers to cause a denial of service (crash) and p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kerio Personal Firewall 2.1.x - Remote Authentication Packet Buffer Overflow (1)
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows r
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mike Bobbitt Album.PL 0.61 - Remote Command Execution
Album.pl 6.1 allows remote attackers to execute arbitrary commands, when an alternative configuration file is used, via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pi3Web 2.0.1 - GET Denial of Service
Buffer overflow in Pi3Web 2.0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitr
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Macromedia ColdFusion MX 6.0 - Error Message Full Path Disclosure
The default configuration of ColdFusion MX has the "Enable Robust Exception Information" option selected, which allows r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Truegalerie 1.0 - Unauthorized Administrative Access
The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PoPToP PPTP 1.1.4-b3 - 'poptop-sane.c' Remote Command Execution
ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length fie
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alt-N WebAdmin 2.0.x - Remote File Disclosure
Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with ad
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alt-N WebAdmin 2.0.x - Remote File Viewing
Absolute path traversal vulnerability in Alt-N Technologies WebAdmin 2.0.0 through 2.0.2 allows remote attackers with ad
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 2000/XP - SMB Authentication Remote Overflow
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 20
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xoops 1.3.x/2.0 MyTextSanitizer - HTML Injection
Cross-site scripting (XSS) vulnerability in the MytextSanitizer function in XOOPS 1.3.5 through 1.3.9 and XOOPS 2.0 thro
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.x - 'enq' Local Buffer Overflow
Buffer overflow in enq command in IBM AIX 4.3.x and earlier may allow local users to execute arbitrary commands via a lo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Libopt.a 3.1x - Error Logging Buffer Overflow (2)
Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Libopt.a 3.1x - Error Logging Buffer Overflow (1)
Multiple buffer overflows in Options Parsing Tool (OPT) shared library 3.18 and earlier, when used in setuid programs, m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Snort 1.9.1 - 'p7snort191.sh' Remote Command Execution
Integer overflow in the TCP stream reassembly module (stream4) for Snort 2.0 and earlier allows remote attackers to exec
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Battleaxe Software BTTLXE Forum - 'login.asp' SQL Injection
SQL injection vulnerability in bttlxeForum 2.0 beta 3 and earlier allows remote attackers to bypass authentication via t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP Database 7.3/7.4 - SDBINST Race Condition
Race condition in SDBINST for SAP database 7.3.0.29 creates critical files with world-writable permissions before initia
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Remote 'URLMON.dll' Remote Buffer Overflow
Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute arbitr
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xinetd 2.1.x/2.3.x - Rejected Connection Memory Leakage Denial of Service
Memory leak in xinetd 2.3.10 allows remote attackers to cause a denial of service (memory consumption) via a large numbe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PoPToP PPTP 1.1.4-b3 - Remote Command Execution
ctrlpacket.c in PoPToP PPTP server before 1.1.4-b3 allows remote attackers to cause a denial of service via a length fie
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.2.4 - DirectoryService 'PATH' Local Privilege Escalation
DirectoryServices in MacOS X trusts the PATH environment variable to locate and execute the touch command, which allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.3.x/5.1 - 'ERRPT' Local Buffer Overflow
Buffer overflow in errpt in AIX 4.3.3 allows local users to execute arbitrary code as root.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Mod_Access_Referer 1.0.2 - Null Pointer Dereference Denial of Service
mod_access_referer 1.0.2 allows remote attackers to cause a denial of service (crash) via a malformed Referer header tha
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IkonBoard 3.1 - Lang Cookie Arbitrary Command Execution (1)
FUNC.pm in IkonBoard 3.1.2a and earlier, including 3.1.1, does not properly cleanse the "lang" cookie when it contains i
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 2.4.20 - Module Loader Privilege Escalation
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.0.44 (Linux) - Remote Denial of Service
A memory leak in Apache 2.0 through 2.0.44 allows remote attackers to cause a denial of service (memory consumption) via
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 2.2.x - 'call_trans2open' Remote Buffer Overflow (1)
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x/2.4.x - Privileged Process Hijacking Privilege Escalation (2)
The kernel module loader in Linux kernel 2.2.x before 2.2.25, and 2.4.x before 2.4.21, allows local users to gain root p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba < 2.2.8 (Linux/BSD) - Remote Code Execution
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.