Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.653VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Microsoft NetMeeting 3.0.1 4.4.3385 - Remote Desktop Sharing Denial of Service
Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utili
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XFree86 3.3.5/3.3.6 - Xlib Display Buffer Overflow
Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY envi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 3.0/4.0 - Error Logging Format String
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary com
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oatmeal Studios Mail File 1.10 - Arbitrary File Disclosure
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nevis Systems All-Mail 1.1 - Remote Buffer Overflow
Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 9x/ME - Share Level Password Bypass (2)
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape iCal 2.1 Patch2 - iPlanet iCal 'iplncal.sh' Permissions
iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal confi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 9x/ME - Share Level Password Bypass (1)
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape iCal 2.1 Patch2 - iPlanet iCal 'csstart' Local Privilege Escalation
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Evolvable Shambala Server 4.5 - Denial of Service
Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
extropia webstore 1.0/2.0 - Directory Traversal
Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remot
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bytes interactive Web shopper 1.0/2.0 - Directory Traversal
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hassan Consulting Shopping Cart 1.18 - Directory Traversal
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpix 1.0 - Directory Traversal
Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat 6.2/7.0 Tmpwatch - Arbitrary Command Execution
Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain she
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Virtual Machine 2000/3100/3200/3300 Series - 'com.ms.activeX.ActiveXComponent' Arbitrary Program Execution
Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX cont
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 2.x - Pending ARP Request Remote Denial of Service
OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 2.x - 'fstat' Format String
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - Indexed Directory Disclosure
A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list direc
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco PIX Firewall 5.2 - PASV Mode FTP Internal Address Disclosure
Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by floo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
David Harris Pegasus Mail 3.12 - File Forwarding
Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol wi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SmartWin CyberOffice Shopping Cart 2.0 - Client Information Disclosure
The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with wo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Smartwin Technology CyberOffice Shopping Cart 2.0 - Price Modification
SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Moreover CGI script - File Disclosure
Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Check Point Software Firewall-1 3.0/1 4.0/1 4.1 - Session Agent Dictionary Attack (2)
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH 1.2 - '.scp' File Create/Overwrite
Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary file
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LBL Traceroute 1.4 a5 - Heap Corruption (3)
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LBL Traceroute 1.4 a5 - Heap Corruption (1)
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LBL Traceroute 1.4 a5 - Heap Corruption (2)
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unixware 7.0 - SCOhelp HTTP Server Format String
Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attacker
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.