Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.409exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.609VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
aolserver 3.2 Win32 - Directory Traversal
Directory traversal vulnerability in AOLserver 3.2 and earlier allows remote attackers to read arbitrary files by insert
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
informs picserver 1.0 - Directory Traversal
Picserver web server allows remote attackers to read arbitrary files via a .. (dot dot) attack in an HTTP GET request.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SSH 1.2.30 - Daemon Logging Failure
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Net.Commerce 2.0/3.x/4.x - orderdspc.d2w order_rn Option SQL Injection
orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Heat-On HSWeb Web Server 2.0 - Full Path Disclosure
HSWeb 2.0 HTTP server allows remote attackers to obtain the physical path of the server via a request to the /cgi/ direc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Guido Frassetto SEDUM HTTP Server 2.0 - Directory Traversal
Directory traversal vulnerability in SEDUM HTTP Server 2.0 allows remote attackers to read arbitrary files via a .. (dot
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.0/2.1 - Directory Traversal
Directory traversal vulnerability in GoAhead web server 2.1 and earlier allows remote attackers to read arbitrary files
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PALS Library System WebPALS 1.0 - 'pals-cgi' Arbitrary Command Execution
PALS Library System pals-cgi program allows remote attackers to execute arbitrary commands via shell metacharacters in t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PALS Library System WebPALS 1.0 - pals-cgi Traversal Arbitrary File Read
Directory traversal vulnerability in PALS Library System pals-cgi program allows remote attackers to read arbitrary file
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xmail 0.5/0.6 CTRLServer - Arbitrary Commands
Buffer overflows in CTRLServer in XMail allows attackers to execute arbitrary commands via the cfgfileget or domaindel f
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 7/8 - ximp40 Library Buffer Overflow
Buffer overflow in ximp40 shared library in Solaris 7 and Solaris 8 allows local users to gain privileges via a long "ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Debian 2.2 / Su.S.E 6.3/6.4/7.0 - man '-l' Format String
Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iweb hyperseek 2000 - Directory Traversal
Directory traversal vulnerability in hsx.cgi program in iWeb Hyperseek 2000 allows remote attackers to read arbitrary fi
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape Enterprise Server 4.0/sparc/SunOS 5.7 - Remote Command Execution
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tru64 5 - 'su' Env Local Stack Overflow
Multiple buffer overflows in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allow local users to gain root privileges via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SCO OpenServer 5.0.5 - Env Local Stack Overflow
Buffer overflow in SCO mscreen allows local users to gain root privileges via a long terminal entry (TERM) in the .mscre
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
splitvt < 1.6.5 - Local Overflow
Multiple buffer overflows in splitvt before 1.6.5 allow local users to execute arbitrary commands.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SCO OpenServer 5.0.5 - Env Local Stack Overflow
Buffer overflow in mscreen on SCO OpenServer 5.0 and SCO UNIX 3.2v4 allows a local user to gain root access via (1) a lo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vim 5.x - Swap File Race Condition
vim (aka gvim) allows local users to modify files being edited by other users via a symlink attack on the backup and swa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
jaZip 0.32-2 - Local Buffer Overflow
Buffer overflow in jaZip Zip/Jaz drive manager allows local users to gain root privileges via a long DISPLAY environment
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/2.7 - '/usr/bin/write' Local Overflow
Buffer overflow in /usr/bin/write in Solaris 2.6 and 7 allows local users to gain privileges via a long string in the te
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
glibc-2.2 / openssh-2.3.0p1 / glibc 2.1.9x - File Read
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variabl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape Enterprise Server 3.0/4.0 - 'Index' Disclosure
The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary direc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 - Networking Mutex Denial of Service
The Winsock2ProtocolCatalogMutex mutex in Windows NT 4.0 has inappropriate Everyone/Full Control permissions, which allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.4.2/2.5/2.6 - Debug Mode Client Hostname Format String
Format string vulnerability in wu-ftp 2.6.1 and earlier, when running with debug mode enabled, allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD 3.x/4.x - 'ipfw' Filtering Evasion
ipfw and ip6fw in FreeBSD 4.2 and earlier allows remote attackers to bypass access restrictions by setting the ECE flag
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LocalWEB2000 1.1 - Directory Traversal
Directory traversal vulnerability in LocalWEB2000 HTTP server allows remote attackers to read arbitrary commands via a .
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Baltimore Technologies WEBsweeper 4.0 - Denial of Service
Websweeper 4.0 does not limit the length of certain HTTP headers, which allows remote attackers to cause a denial of ser
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
fastream ftp++ 2.0 - Directory Traversal
FaSTream FTP++ Server 2.0 allows remote attackers to list arbitrary directories by using the "ls" command and including
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eEye Digital Security IRIS 1.0.1 - GET Denial of Service
eEye Iris 1.01 beta allows remote attackers to cause a denial of service via a malformed packet, which causes Iris to cr
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.