Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.284GitHub PoC 15.675VulnCheck XDB 9136Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Resolv+ 'RESOLV_HOST_CONF' - Linux Library Command Execution
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variabl
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
John S.2 Roberts AnyForm 1.0/2.0 - CGI Semicolon
AnyForm CGI remote execution.
53RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IRIX 5.2/6.0 - Permissions File Manipulation
SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NCSA HTTPd 1.x - Remote Buffer Overflow (2)
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NCSA HTTPd 1.x - Remote Buffer Overflow (2)
Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.0.1 - 'colorview' Read Files
colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argume
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Majordomo 1.89/1.90 - 'lists' Command Execution
Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sendmail 8.6.9 IDENT - Remote Command Execution
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 10/11/ IRIX 3/4/5/6 / OpenSolaris build snv / Solaris 8/9/10 / SunOS 4.1 - 'rpc.ypupdated' Command Execution (1)
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 10/11/ IRIX 3/4/5/6 / OpenSolaris build snv / Solaris 8/9/10 / SunOS 4.1 - 'rpc.ypupdated' Command Execution (2)
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 5.2/5.3 - 'serial_ports' Local Privilege Escalation
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SunOS 4.1.4 - arp(8c) Memory Dump
Solaris arp allows local users to read files via the -f parameter, which lists lines in the file that do not parse prope
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Digital Ultrix 4.0/4.1 - '/usr/bin/chroot' Local Privilege Escalation
chroot in Digital Ultrix 4.1 and 4.0 is insecurely installed, which allows local users to gain privileges.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SunView (SunOS 4.1.1) - 'selection_svc' Remote File Read
The SunView (SunTools) selection_svc facility allows remote users to read files.
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Intel Corporation Express 8100 ISDN Router - Fragmented ICMP
The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Berkeley Sendmail 5.58 - Debug
The debug command in Sendmail is enabled, allowing attackers to execute commands as root.
28RIESGO
abrir ↗Referência✓ VexDay Proof
SCO UnixWare < 7.1.4 p534589 - 'pkgadd' Local Privilege Escalation
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append
23RIESGO
abrir ↗Referência✓ VexDay Proof
pHNews Alpha 1 - 'genbackup.php' Database Disclosure
pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir ↗Referência✓ VexDay Proof
Aria 0.99-6 - 'page' Local File Inclusion
Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
MailBee WebMail Pro 4.1 - Remote File Disclosure
Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET all
28RIESGO
abrir ↗Referência✓ VexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
login.php in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allows remote attackers to bypass authentication and obta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords
23RIESGO
abrir ↗Referência✓ VexDay Proof
Gradman 0.1.3 - 'info.php' Local File Inclusion
Directory traversal vulnerability in info.php in GradMan 0.1.3 and earlier allows remote attackers to include and execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion Mod E-Cart 1.3 - 'items.php' SQL Injection
SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbi
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure
Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary l
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyKtools 2.4 - 'langage' Local File Inclusion
Directory traversal vulnerability in update.php in MyKtools 2.4 allows remote attackers to include and execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
aflog 1.01 - Cross-Site Scripting / SQL Injection
Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Frimousse 0.0.2 - 'explorerdir.php' Local Directory Traversal
Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary fi
23RIESGO
abrir ↗Referência✓ VexDay Proof
bloofox 0.3 - SQL Injection / File Disclosure
Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pluck CMS 4.6.2 - 'langpref' Local File Inclusion
Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.