Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.653VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Debian 2.1/2.2 / Mandrake 6.0/6.1/7.0 / RedHat 6.x - 'rpc.lockd' Remote Denial of Service
rpc.lockd in Red Hat Linux 6.1 and 6.2 allows remote attackers to cause a denial of service via a malformed request.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 - Remote Registry Request Denial of Service (MS00-040) (2)
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malform
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 - Remote Registry Request Denial of Service (1)
The Remote Registry server in Windows NT 4.0 allows local authenticated users to cause a denial of service via a malform
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Stelian Pop dump 0.4 - restore Buffer Overflow
Buffer overflow in restore program 0.4b17 and earlier in dump package allows local users to execute arbitrary commands v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 10.20/11.0 - '.SNMPD' File Permission
The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Computer Associates eTrust Intrusion Detection 1.4.1.13 - Weak Encryption
eTrust Intrusion Detection System (formerly SessionWall-3) uses weak encryption (XOR) to store administrative passwords
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x 2.4.0-test1 (SGI ProPack 1.2/1.3) - Sendmail Capabilities Privilege Escalation(1)
The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ColdFusion Server 2.0/3.x/4.x - Administrator Login Password Denial of Service
ColdFusion Administrator for ColdFusion 4.5.1 and earlier allows remote attackers to cause a denial of service via a lon
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x 2.4.0-test1 (SGI ProPack 1.2/1.3) - Sendmail 8.10.1 Capabilities Privilege Escalation (2)
The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Intel Corporation Shiva Access Manager 5.0 - Solaris World Readable LDAP Password
When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mirabilis ICQ 2000.0 A - Mailclient Temporary Link
ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Michael Lamont Savant Web Server 2.1 - CGI Source Code Disclosure
Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BRU 15.1/16.0 - BRUEXECLOG Environment Variable
BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PassWD 1.2 - Weak Encryption
PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the passwor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 10.20/11.0 - man '/tmp' Symlink
man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BSD 'mailx' 8.1.1-10 - Local Buffer Overflow (1)
Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetWin DMail 2.7/2.8 - ETRN Buffer Overflow
Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary comman
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Atrus Trivalie Productions Simple Network Time Sync 1.0 - daemon Buffer Overflow
Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sam Lantinga splitvt 1.6.3 - Local Buffer Overflow
Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OReilly Software WebSite Professional 2.3.18/2.4/2.4.9 - 'webfind.exe' Remote Buffer Overflow
Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execut
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Allegro RomPager 2.10 - URL Request Denial of Service
Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Concatus IMate Web Mail Server 2.5 - Remote Buffer Overflow
Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Real Networks Real Server 7.0/7.0.1/8.0 Beta - view-source Denial of Service
Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE 1.1.2 KApplication configfile - Local Privilege Escalation (3)
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Media Services 4.0/4.1 - Denial of Service (MS00-038)
Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "M
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3.6/1.3.9/1.3.11/1.3.12/1.3.20 - Root Directory Access
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a UR
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE 1.1.2 KApplication configfile - Local Privilege Escalation (1)
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
KDE 1.1.2 KApplication configfile - Local Privilege Escalation (2)
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Eterm 0.8.10 / rxvt 2.6.1 / PuTTY 0.48 / X11R6 3.3.3/4.0 - Denial of Service
xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mandriva Linux Mandrake 7.0 - Local Buffer Overflow
Buffer overflow in Linux cdrecord allows local users to gain privileges via the dev parameter.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.