Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.407exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.608VulnCheck XDB 9133Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
HP OpenView OmniBack II A.03.50 - Command Execution (Metasploit)
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack c
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sapio WebReflex 1.55 - GET Denial of Service
Buffer overflow in WebReflex 1.55 HTTPd allows remote attackers to cause a denial of service, and possibly execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Robin Twombly A1 HTTP Server 1.0 - Directory Traversal
Directory traversal vulnerability in A1 HTTP server 1.0a allows remote attackers to read arbitrary files via a .. (dot d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11.x/12.0 - ILMI SNMP Community String
Cisco IOS 11.x and 12.0 with ATM support allows attackers to cause a denial of service via the undocumented Interim Loca
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Orange Software Orange Web Server 2.1 - Denial of Service
Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
APC WEB/SNMP Management Card (9606) Firmware 3.0 - Telnet Administration Denial of Service
APC Web/SNMP Management Card prior to Firmware 310 only supports one telnet connection, which allows a remote attacker t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Atrium Software Mercur Mail Server 3.3 - EXPN Buffer Overflow
Buffer overflow in MERCUR SMTP server 3.30 allows remote attackers to execute arbitrary commands via a long EXPN command
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sudo 1.5/1.6 - Heap Corruption
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.2.7 - Full Path Disclosure
ext.dll in BadBlue 1.02.07 Personal Edition web server allows remote attackers to determine the physical path of the ser
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.2.7 - Denial of Service
Buffer overflow in ext.dll in BadBlue 1.02.07 Personal Edition allows remote attackers to cause a denial of service and
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Marconi ASX-1000 - Administration Denial of Service
Marconi ASX-1000 ASX switches allow remote attackers to cause a denial of service in the telnet and web management inter
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adcycle 0.77/0.78 - AdLibrary.pm Session Access
AdLibrary.pm in AdCycle 0.78b allows remote attackers to gain privileges to AdCycle via a malformed Agent: header in the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
itafrica webactive 1.0 - Directory Traversal
Directory traversal vulnerability in ITAfrica WEBactive HTTP Server 1.00 allows remote attackers to read arbitrary files
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
thinking arts es.one 1.0 - Directory Traversal
Directory traversal vulnerability in store.cgi in Thinking Arts ES.One package allows remote attackers to read arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
caucho Technology resin 1.2 - Directory Traversal
Directory traversal vulnerability in Caucho Resin 1.2.2 allows remote attackers to read arbitrary files via a "\.." (dot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bajie WebServer 0.78/0.90 - Remote Command Execution
UploadServlet in Bajie HTTP JServer 0.78, and possibly other versions before 0.80, allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bajie 0.78 - Arbitrary Shell Command Execution
Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
John Roy Pi3Web 1.0.1 - Buffer Overflow
Buffer overflow in tstisapi.dll in Pi3Web 1.0.1 web server allows remote attackers to cause a denial of service, and pos
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KICQ 1.0 - Arbitrary Command Execution
kicq IRC client 1.0.0, and possibly later versions, allows remote attackers to execute arbitrary commands via shell meta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Way-Board 2.0 - File Disclosure
Way-board CGI program allows remote attackers to read arbitrary files by specifying the filename in the db parameter and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Martin Hamilton ROADS 2.3 - File Disclosure
ROADS search.pl program allows remote attackers to read arbitrary files by specifying the file name in the form paramete
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Brightstation Muscat 1.0 - Full Path Disclosure
Muscat Empower CGI program allows remote attackers to obtain the absolute pathname of the server via an invalid request
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
his software auktion 1.62 - Directory Traversal
Directory traversal vulnerability in HIS Auktion 1.62 allows remote attackers to read arbitrary files via a .. (dot dot)
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
carey internets services commerce.cgi 2.0.1 - Directory Traversal
Directory traversal vulnerability in commerce.cgi CGI program allows remote attackers to read arbitrary files via a .. (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SilverPlatter WebSPIRS 3.3.1 - File Disclosure
Directory traversal vulnerability in WebSPIRS 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Micro Focus Cobol 4.1 - Arbitrary Command Execution
MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with inse
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x - 'sysctl()' Memory Reading
Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SSH 1.2.x - CRC-32 Compensation Attack Detector
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
soft lite serverworx 3.0 - Directory Traversal
Directory traversal vulnerability in Soft Lite ServerWorx 3.00 allows remote attackers to read arbitrary files by insert
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
aolserver 3.2 Win32 - Directory Traversal
Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by insert
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.