Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.653VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Palm OS 3.5.2 - Weak Encryption
PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager 6.10 - SNMP Denial of Service
Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attacke
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Script Host 5.1/5.5 - 'GetObject()' File Disclosure
Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetO
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Media Player 7 - Embedded OCX Control
Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embed
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.4.2/2.5 .0/2.6.0 - Remote Format String Stack Overwrite (2)
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Alabanza Control Panel 3.0 - Domain Modification
The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
UoW Pine 4.0.4/4.10/4.21 - 'From:' Remote Buffer Overflow
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arb
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetcPlus BrowseGate 2.80 - Denial of Service
BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Au
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SuSE Linux 6.3/6.4 - Installed Package Disclosure
The default configuration of Apache (httpd.conf) on SuSE 6.4 includes an alias for the /usr/doc directory, which allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
extent technologies rbs isp 2.5 - Directory Traversal
Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Secure ACS for Windows NT 2.42 - Remote Buffer Overflow
Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco PIX Firewall 4.x/5.x - SMTP Content Filtering Evasion
The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/2000 - DLL Search Path
When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sambar Server 4.3/4.4 Beta 3 - Search CGI
search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CamShot WebCam 2.6 Trial - Remote Buffer Overflow
Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorizatio
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Websphere Application Server 3.0.2 Server Plugin - Denial of Service
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MultiHTML 1.5 - File Disclosure
MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifyi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebTV for Windows 98/ME - Denial of Service
annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP pac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jack De Winter WinSMTP 1.6 f/2.0 - Buffer Overflow
Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2)
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mandrake 6.1/7.0/7.1 - '/perl' HTTP Directory Disclosure
The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ director
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YaBB 9.1.2000 - Arbitrary File Read
YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 6.1 i386 - Tmpwatch Recursive Write Denial of Service
The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mobius DocumentDirect for the Internet 1.2 - Remote Buffer Overflow
Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0 'eject' locale - Subsystem Format String
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3.12 - WebDAV Directory Listings
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbit
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
nathan purciful phpphotoalbum 0.9.9 - Directory Traversal
explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LPPlus 3.2.2/3.3 - dccscan Unprivileged read
The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LPPlus 3.2.2/3.3 - Permissions Denial of Service
LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Still Image Service Privilege Escalation
Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long W
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat 6 GLIBC/locale - Subsystem Format String
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.