Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.653VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
AnalogX Proxy 4.0 4 - Denial of Service
Buffer overflow in AnalogX proxy server 4.04 and earlier allows remote attackers to cause a denial of service via a long
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape Communicator 4.x - JPEG-Comment Heap Overwrite
Netscape Communicator 4.73 and earlier allows remote attackers to cause a denial of service or execute arbitrary command
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Websphere Application Server 2.0./3.0/3.0.2.1 - Showcode
IBM WebSphere allows remote attackers to read source code for executable web files by directly calling the default Invok
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WFTPD 2.4.1RC11 - 'REST' Malformed File Write Denial of Service
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by using the RESTART (REST) command and wr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WFTPD 2.4.1RC11 - 'STAT'/'LIST' Denial of Service
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing a STAT command while the LIST
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Roxen WebServer 2.0.x - '%00' Request File/Directory Disclosure
Roxen web server earlier than 2.0.69 allows allows remote attackers to bypass access restrictions, list directory conten
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WFTPD 2.4.1RC11 - 'MLST' Remote Denial of Service
WFTPD and WFTPD Pro 2.41 allows remote attackers to cause a denial of service by executing an MLST command before loggin
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tomcat 3.0/3.1 Snoop Servlet - Information Disclosure
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 3.1 - Path Revealing
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not ex
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP JetDirect J3111A - Invalid FTP Command Denial of Service
HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Computer Software Manufaktur Alibaba 2.0 - Denial of Service
Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetZero ZeroPort 3.0 - Weak Encryption Method
NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decryp
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Computer Software Manufaktur Alibaba 2.0 - Piped Command
Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 97/98/2000 / Outlook Express 4.0/5.0 - GMT Field Buffer Overflow (1)
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a lon
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 97/98/2000 / Outlook Express 4.0/5.0 - GMT Field Buffer Overflow (2)
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a lon
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Armada Design Master Index 1.0 - Directory Traversal
Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetZero ZeroPort 3.0 - Weak Encryption Method
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile an
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Source Fragment Disclosure
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (1)
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, wh
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AnalogX SimpleServer:WWW 1.0.5 - Denial of Service
Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET reques
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 2.0/3.0/4.0/5.0/5.1 - Internal IP Address Disclosure
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Infopulse GateKeeper 3.5 - Remote Buffer Overflow
Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
alt-n WorldClient standard 2.1 - Directory Traversal
The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CVSWeb Developer CVSWeb 1.80 - Insecure Perl 'open' Code Execution
The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Netware 5.0 SP5/6.0 SP1 - SMDR.NLM Denial of Service
Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Texas Imperial Software WFTPD 2.4.1 - RNTO Denial of Service
WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command befor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sean MacGuire Big Brother 1.x - Directory Traversal
bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PIX Firewall 2.7/3.x/4.x/5 - Forged TCP RST
Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to fo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DrPhibez and Nitro187 Guild FTPD 0.9.7 - File Existence Disclosure
Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BitchX IRC Client 75p1/75p3/1.0 c16 - '/INVITE' Format String
BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.