Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
PHP-Nuke Network Tool 0.2 Addon - MetaCharacter Filtering Command Execution
Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ActivePerl 5.6.1 - 'perlIIS.dll' Remote Buffer Overflow (2)
Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitra
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 5.0/5.1 - Same Origin Policy Circumvention
Opera 6.0 and earlier allows remote attackers to access sensitive information such as cookies and links for other domain
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ActivePerl 5.6.1 - 'perlIIS.dll' Remote Buffer Overflow (3)
Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitra
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ActivePerl 5.6.1 - 'perlIIS.dll' Remote Buffer Overflow (1)
Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitra
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rational ClearCase 3.2/4.x - DB Loader TERM Environment Variable Buffer Overflow
Buffer overflow in db_loader in ClearCase 4.2 and earlier allows local users to gain root privileges via a long TERM env
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - Cookie Disclosure/Modification
Internet Explorer 5.5 and 6.0 allows remote attackers to read and modify user cookies via Javascript in an about: URL, a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Horde IMP 2.2.x - Session Hijacking
Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain acces
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat TUX 2.1.0-2 - HTTP Server Oversized Host Denial of Service
TUX HTTP server 2.1.0-2 in Red Hat Linux allows remote attackers to cause a denial of service via a long Host: header.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sudo 1.6.x - Password Prompt Heap Overflow
Sudo before 1.6.6 contains an off-by-one error that can result in a heap-based buffer overflow that may allow local user
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000 - GDI Denial of Service
Win32k.sys (aka Graphics Device Interface (GDI)) in Windows 2000 and XP allows local users to cause a denial of service
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iBill Management Script - Weak Hard-Coded Password
ibillpm.pl in iBill password management system generates weak passwords based on a client's MASTER_ACCOUNT, which allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
6Tunnel 0.6/0.7/0.8 - Connection Close State Denial of Service
6tunnel 0.08 and earlier does not properly close sockets that were initiated by a client, which allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - JavaScript Interface Spoofing
Internet Explorer 6 and earlier allows remote attackers to create chromeless windows using the Javascript window.createP
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mountain Network Systems WebCart 8.4 - Command Execution
webcart.cgi in Mountain Network Systems WebCart 8.4 allows remote attackers to execute arbitrary commands via shell meta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2/2.4 - Ptrace/Setuid Exec Privilege Escalation
ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT/2000 - Terminal Server Service RDP Denial of Service
Terminal Server in Windows NT and Windows 2000 allows remote attackers to cause a denial of service via a sequence of in
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle9iAS Web Cache 2.0 - Remote Buffer Overflow
Buffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET re
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2/2.4 - Deep Symbolic Link Denial of Service
Linux kernel 2.2.1 through 2.2.19, and 2.4.1 through 2.4.10, allows local users to cause a denial of service via a serie
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Snes9x 1.3 - Local Buffer Overflow
Buffer overflow in Snes9x 1.37, when installed setuid root, allows local users to gain root privileges via a long comman
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PostNuke 0.6 - User Login
SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authenticatio
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Zone Spoofing (MS01-055)
Internet Explorer 5.5 and 5.01 allows remote attackers to bypass security restrictions via malformed URLs that contain d
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Progress Database 8.3/9.1 - Multiple Buffer Overflows
Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AmTote Homebet - World Accessible Log
AmTote International homebet program stores the homebet.log file in the homebet/ virtual directory, which allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Amtote Homebet - Account Information Brute Force
AmTote International homebet program returns different error messages when invalid account numbers and PIN codes are pro
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3Com OfficeConnect DSL Router 812 1.1.7/840 1.1.7 - HTTP Port Router Denial of Service
3COM OfficeConnect 812 and 840 ADSL Router 4.2, running OCR812 router software 1.1.9 and earlier, allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD 4.3/4.4 - Login Capabilities Privileged File Reading
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 - File Information / Full Path Disclosure
SQLQHit.asp sample file in Microsoft Index Server 2.0 allows remote attackers to obtain sensitive information such as th
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Stalker Internet Mail Server 1.6 - Remote Buffer Overflow
Stalker Internet Mail Server 1.6 allows a remote attacker to cause a denial of service (crash) via a long HELO command.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 7.0 Apache - Remote Username Enumeration
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists a
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.