Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.366exploits catalogados
37.872CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.213GitHub PoC 15.592VulnCheck XDB 9133Nuclei 4441Metasploit 3505✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0/5.0 - PWS Escaped Characters Decoding Command Execution (2)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iPlanet 4.1 Web Publisher - Remote Buffer Overflow (1)
Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cau
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0/5.0 - PWS Escaped Characters Decoding Command Execution (5)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0/5.0 - PWS Escaped Characters Decoding Command Execution (4)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0/5.0 - PWS Escaped Characters Decoding Command Execution (7)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Maxum Rumpus FTP Server 1.3.2/1.3.4/2.0.3 dev - Remote Denial of Service
Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0/5.0 - PWS Escaped Characters Decoding Command Execution (8)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0/5.0 - PWS Escaped Characters Decoding Command Execution (6)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iPlanet 4.1 Web Publisher - Remote Buffer Overflow (2)
Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cau
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0/5.0 - PWS Escaped Characters Decoding Command Execution (1)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0/5.0 - PWS Escaped Characters Decoding Command Execution (3)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pacific Software Carello 1.2.1 Shopping Cart - Command Execution
Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary comman
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Immunix OS 6.2/7.0 / RedHat 5.2/6.2/7.0 / SuSE Linux 6.x/7.0/7.1 - 'Man -S' Heap Overflow
Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group ma
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Personal Web Sharing 1.1/1.5/1.5.5 - Remote Denial of Service
Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenServer 5.0.5/5.0.6 / HP-UX 10/11 / Solaris 2.6/7.0/8 - rpc.yppasswdd Buffer Overrun
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access v
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DCForum 6.0 - Remote Admin Privilege Arbitrary Commands
DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symb
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 SP1/SP2 - isapi .printer Extension Overflow (2)
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BeroFTPD 1.3.4(1) (Linux x86) - Remote Code Execution
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IRIX 5.3/6.2/6.3/6.4/6.5/6.5.11 - '/usr/lib/print/netprint' Local Privilege Escalation
Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drummond Miles A1Stats 1.0 - 'a1disp3.cgi' Traversal Arbitrary File Read
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary file
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drummond Miles A1Stats 1.0 - 'a1disp2.cgi' Traversal Arbitrary File Read
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary file
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IRIX 5.3/6.2/6.3/6.4/6.5/6.5.11 - '/usr/bin/lpstat' Local Overflow / Local Privilege Escalation
Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SpyNet 6.5 Chat Server - Multiple Connection Denial of Service Vulnerabilities
Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of conn
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
T. Hauck Jana Server 1.45/1.46 - Hex Encoded Directory Traversal
T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack wh
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vixie Cron crontab 3.0 - Privilege Lowering Failure (1)
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification ope
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hughes Technologies DSL_Vdns 1.0 - Denial of Service
Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SCO OpenServer 5.0.x - StartX Weak XHost Permissions
SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell BorderManager Enterprise Edition 3.5 - Denial of Service
Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ElectroSoft ElectroComm 1.0/2.0 - Denial of Service
ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jason Rahaim MP3Mystic 1.0.x - Server Directory Traversal
Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.