Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows 98/XP/ME - UPnP NOTIFY Buffer Overflow (2)
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arb
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 98/XP/ME - UPnP NOTIFY Buffer Overflow (1)
Buffer overflow in Universal Plug and Play (UPnP) on Windows 98, 98SE, ME, and XP allows remote attackers to execute arb
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris /bin/login (SPARC/x86) - Remote Code Execution
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alteon AceDirector - Half-Closed HTTP Request IP Address Revealing
Nortel Alteon ACEdirector WebOS 9.0, with the Server Load Balancing (SLB) and Cookie-Based Persistence features enabled,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZYXEL Prestige 681 SDSL Router - IP Fragment Reassembly
Zyxel Prestige 681 and 1600 SDSL Routers allow remote attackers to cause a denial of service via malformed packets with
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aktivate 1.0 3 - Shopping Cart Cross-Site Scripting
Cross-site scripting vulnerability in catgy.cgi for Aktivate 1.03 allows remote attackers to execute arbitrary Javascrip
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QPopper 4.0.x - PopAuth Trace File Shell Command Execution
popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Agora.CGI 3.x/4.0 - Debug Mode Cross-Site Scripting
Cross-site scripting vulnerability in agora.cgi for Agora 3.0a through 4.0g, when debug mode is enabled, allows remote a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
webmin 0.91 - Directory Traversal
Directory traversal vulnerability in edit_action.cgi of Webmin Directory 0.91 allows attackers to gain privileges via a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Groupwise 5.5/6.0 Servlet Gateway - Default Authentication
Novell Groupwise 5.5 and 6.0 Servlet Gateway is installed with a default username and password for the servlet manager,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
System V Derived /bin/login - Extraneous Arguments Buffer Overflow (modem based) (Metasploit)
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6.0 / Mozilla 0.9.6 / Opera 5.1 - Image Count Denial of Service
Mozilla 0.9.6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6.0 / Mozilla 0.9.6 / Opera 5.1 - Image Count Denial of Service
Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Brian Dorricott MAILTO 1.0.7-9 - Unauthorized Mail Server Use
mailto.exe in Brian Dorricott MAILTO 1.0.9 and earlier allows remote attackers to send SPAM e-mail through remote server
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - RunAs Service Denial of Service
RunAs (runas.exe) in Windows 2000 only creates one session instance at a time, which allows local users to cause a denia
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - RunAs Service Named Pipe Hijacking
RunAs (runas.exe) in Windows 2000 allows local users to create a spoofed named pipe when the service is stopped, then ca
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6.0 / Mozilla 0.9.6 / Opera 5.1 - Image Count Denial of Service
Opera 5.11 allows remote attackers to cause a denial of service (CPU consumption and memory leak) via a web page with a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - False Content-Length Field Denial of Service
Microsoft IIS 5.0 allows remote attackers to cause a denial of service via an HTTP request with a content-length value t
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Internet Key Exchange Denial of Service (1)
Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (I
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Denicomp Winsock RSHD/NT Standard Error 2.20.00 - Denial of Service
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Denicomp Winsock RSHD/NT Standard Error 2.21.00 - Denial of Service
wrshdsp.exe in Denicomp Winsock RSHD/NT 2.21.00 and earlier allows remote attackers to cause a denial of service (CPU co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD 4.4 - AIO Library Cross Process Memory Write
Some AIO operations in FreeBSD 4.4 may be delayed until after a call to execve, which could allow a local user to overwr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Volition Red Faction 1.0/1.1 - Game Server/Client Denial of Service
THQ Volition Red Faction Game allows remote attackers to cause a denial of service (hang) of a client or server via pack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
McKesson Pathways Homecare 6.5 - Weak 'Username' and Password Encryption
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Internet Key Exchange Denial of Service (2)
Windows 2000 allows remote attackers to cause a denial of service (CPU consumption) by flooding Internet Key Exchange (I
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZoneAlarm Pro 1.0/2.x - Outbound Packet Bypass
Tiny Personal Firewall 1.0 and 2.0 allows local users to bypass filtering via non-standard TCP packets created with non-
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x - 'user.php?uname' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 1.0/2.5/3.0/4.x/5.x/6.x/7.x - 'modules.php' Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in PHP-Nuke 5.3.1 and earlier allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 2.x/3.0 - User Mode Return Value Denial of Service
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EasyNews 1.5 - NewsDatabase/Template Modification
Directory traversal vulnerability in the comments action in easyNews 1.5 and earlier allows remote attackers to modify n
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.