Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.453exploits catalogados
37.908CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.653VulnCheck XDB 9134Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
QSSL QNX 4.25 A - 'crypt()' Local Privilege Escalation
The crypt function in QNX uses weak encryption, which allows local users to decrypt passwords.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft FrontPage 98 Server Extensions for IIS / Microsoft InterDev 1.0 - Remote Buffer Overflow
Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or exec
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft FrontPage 98 Server Extensions for IIS / Microsoft InterDev 1.0 - Filename Obfuscation
Buffer overflow in the dvwssr.dll DLL in Microsoft Visual Interdev 1.0 allows users to cause a denial of service or exec
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dansie Shopping Cart 3.0.4 - Multiple Vulnerabilities
The dansie shopping cart application cart.pl allows remote attackers to obtain the shopping cart database and configurat
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CNC Technology BizDB 1.0 - 'bizdb-search.cgi' Remote Command Execution
The BizDB CGI script bizdb-search.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AVM KEN! 1.3.10/1.4.30 - Remote Denial of Service
The AVM KEN! ISDN Proxy server allows remote attackers to cause a denial of service via a malformed request.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TalentSoft Web+ 4.x - Directory Traversal
TalentSoft webpsvr daemon in the Web+ shopping cart application allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bray Systems Linux Trustees 1.5 - Long Pathname
The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a lo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CRYPTOCard CRYPTOAdmin 4.1 - Weak Encryption (2)
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with acces
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Be BeOS 4.5/5.0 - Invalid System Call
BeOS 4.5 and 5.0 allow local users to cause a denial of service via malformed direct system calls using interrupt 37.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CRYPTOCard CRYPTOAdmin 4.1 - Weak Encryption (1)
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with acces
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (3)
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Be BeOS 4.0/4.5/5.0 - IP Packet Length Field
BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the leng
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape PublishingXPert 2.0/2.2/2.5 - Local File Reading
PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec pcAnywhere 9.0 - Weak Encryption
The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebObjects Developer NT4 IIS4.0 CGI-adapter 4.5 - Developer Remote Overflow
Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Stalker CommuniGate Pro 3.2.4 - Arbitrary File Read
The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Real Networks RealPlayer 6/7 - Location Buffer Overflow
Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of serv
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 - '%20' ASP Source Disclosure
Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename i
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SalesLogix Corporation eViewer 1.0 - Denial of Service
The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll admi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt RaQ 2.0/3.0 - Apache .htaccess Disclosure
The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0 - UNC Mapped Virtual Host
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, wh
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/2000 - TCP/IP Printing Service Denial of Service
Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Metaframe 1.0/1.8 - Weak Encryption
The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 5.x/6.x - Objectserver
Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GeoCel WindMail 3.0 - Remote File Read
WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
qDecoder 4.x/5.x - Remote Buffer Overflow
Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, all
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AnalogX SimpleServer:WWW 1.0.3 - Denial of Service
AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Standard & Poors ComStock 4.2.4 - Command Execution
The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.12/2.2.14/2.3.99 (RedHat 6.x) - Socket Denial of Service
The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.