Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Sambar Server 4.x/5.0 - Insecure Default Password Protection
The default configuration of Sambar Server 5 and earlier uses a symmetric key that is compiled into the binary program f
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 12 - UDP Denial of Service
Cisco routers and switches running IOS 12.0 through 12.2.1 allows a remote attacker to cause a denial of service via a f
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Proxomitron Naoko-4 - Cross-Site Scripting
Cross-site scripting vulnerability in Proxomitron Naoko-4 BetaFour and earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0 - DTMail Mail Environment Variable Buffer Overflow
Buffer overflow in dtmail in Solaris 2.6 and 7 allows local users to gain privileges via the MAIL environment variable.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sambar Server 4.4/5.0 - 'pagecount' File Overwrite
Directory traversal vulnerability in pagecount CGI script in Sambar Server before 5.0 beta 5 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CGIWrap 2.x/3.x - Cross-Site Scripting
Cross-site scripting vulnerability in CGIWrap before 3.7 allows remote attackers to execute arbitrary Javascript on othe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPLib Team PHPLIB 7.2 - Remote Script Execution
prepend.php3 in PHPLib before 7.2d, when register_globals is enabled for PHP, allows remote attackers to execute arbitra
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SSH2 3.0 - Short Password Login
SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 8i - TNS Listener Buffer Overflow
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers t
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetWin DMail 2.x / SurgeFTP 1.0/2.0 - Weak Password Encryption
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.x/7.0/8 / IRIX 6.5.x / OpenBSD 2.x / NetBSD 1.x / Debian 3 / HP-UX 10 - 'TelnetD' Remote Buffer Overflow
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbit
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Check Point Firewall-1 4.x - SecuRemote Internal Interface Address Information Leakage
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ID Software Quake 1.9 - Denial of Service
Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconne
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Check Point Firewall-1 4 Securemote - Network Information Leak
The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configura
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Interactive story 1.3 - Directory Traversal
Directory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote attacker to read arbitrary files
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Debian 2.2 /usr/bin/pileup - Local Privilege Escalation
Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3Com SuperStack II PS Hub 40 - TelnetD Weak Password Protection
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ArGoSoft FTP Server 1.2.2.2 - Weak Password Encryption
ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the passwor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 98/2000/2002 - Arbitrary Code Execution
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrar
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 98/2000/2002 - Unauthorized Email Access
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrar
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (2)
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (1)
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (3)
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3 - Directory Index Disclosure
Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (3)
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (2)
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
xloadimage 4.1 - Remote Buffer Overflow
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 11 / Linux Kernel 2.4 / Windows 2000/NT 4.0 / IRIX 6.5 - Small TCP MSS Denial of Service
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Basilix Webmail 1.0 - File Disclosure
Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt Qube Webmail 1.0 - Directory Traversal
Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbit
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.