Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Vixie Cron crontab 3.0 - Privilege Lowering Failure (2)
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification ope
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt Raq3 PopRelayD - Arbitrary SMTP Relay
poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by caus
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Device File Remote Denial of Service
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial o
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lmail 2.7 - Temporary File Race Condition
Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Device File Local Denial of Service
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial o
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Nfuse 1.51 - Webroot Disclosure
Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xvt 2.1 - Local Buffer Overflow
Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.x - SafeMode Arbitrary File Execution
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows lo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Active Classifieds 1.0 - Arbitrary Code Execution
admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xinetd 2.1.8 - Remote Buffer Overflow
Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a lo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (2)
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (4)
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.x - HTTP Configuration Arbitrary Administrative Access (1)
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 8 libsldap - Local Buffer Overflow (2)
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 8 libsldap - Local Buffer Overflow (1)
Buffer overflow in the LDAP naming services library (libsldap) in Sun Solaris 8 allows local users to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Icecast 1.1.x/1.3.x - Slash File Name Denial of Service
Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Icecast 1.1.x/1.3.x - Directory Traversal
Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a mo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10 - nidump Password File Disclosure
nidump on MacOS X before 10.3 allows local users to read the encrypted passwords from the password file by specifying pa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XFree86 X11R6 3.3 XDM - Session Cookie Guessing
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU groff 1.1x - xploitation Via LPD
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote att
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 2.0.x/2.2 - Arbitrary File Creation
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remot
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
teTeX 1.0.7 - Filters Temporary File Race Condition
teTeX filter before 1.0.7 allows local users to gain privileges via a symlink attack on temporary files that are produce
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE KTVision 0.1 - File Overwrite
KDE ktvision 0.1.1-271 and earlier allows local attackers to gain root privileges via a symlink attack on a user configu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (2)
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eXtremail 1.x/2.1 - Remote Format String (2)
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privile
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Studio RAD Support - Remote Buffer Overflow
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attack
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Visual Studio RAD Support - Remote Buffer Overflow (MS03-051) (Metasploit)
Buffer overflow in Microsoft Visual Studio RAD Support sub-component of FrontPage Server Extensions allows remote attack
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
1C: Arcadia Internet Store 1.0 - Path Disclosure
tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to discover the full path to the working directory v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
1C: Arcadia Internet Store 1.0 - Arbitrary File Disclosure
Directory traversal vulnerability in tradecli.dll in Arcadia Internet Store 1.0 allows a remote attacker to read arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eXtremail 1.x/2.1 - Remote Format String (1)
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privile
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.