Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB✓ VexDay Proof
Oracle 8i - TNS Listener Buffer Overflow
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers t
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.x/7.0/8 / IRIX 6.5.x / OpenBSD 2.x / NetBSD 1.x / Debian 3 / HP-UX 10 - 'TelnetD' Remote Buffer Overflow
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbit
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Check Point Firewall-1 4.x - SecuRemote Internal Interface Address Information Leakage
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Check Point Firewall-1 4 Securemote - Network Information Leak
The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configura
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ID Software Quake 1.9 - Denial of Service
Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconne
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Interactive story 1.3 - Directory Traversal
Directory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote attacker to read arbitrary files
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Debian 2.2 /usr/bin/pileup - Local Privilege Escalation
Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
3Com SuperStack II PS Hub 40 - TelnetD Weak Password Protection
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ArGoSoft FTP Server 1.2.2.2 - Weak Password Encryption
ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the passwor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 98/2000/2002 - Arbitrary Code Execution
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrar
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 98/2000/2002 - Unauthorized Email Access
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrar
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (2)
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
xloadimage 4.1 - Remote Buffer Overflow
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3 - Directory Index Disclosure
Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (3)
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (2)
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (3)
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (1)
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 11 / Linux Kernel 2.4 / Windows 2000/NT 4.0 / IRIX 6.5 - Small TCP MSS Denial of Service
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Basilix Webmail 1.0 - File Disclosure
Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt Qube Webmail 1.0 - Directory Traversal
Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vixie Cron crontab 3.0 - Privilege Lowering Failure (2)
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification ope
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Device File Remote Denial of Service
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial o
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt Raq3 PopRelayD - Arbitrary SMTP Relay
poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by caus
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Device File Local Denial of Service
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial o
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lmail 2.7 - Temporary File Race Condition
Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xvt 2.1 - Local Buffer Overflow
Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Nfuse 1.51 - Webroot Disclosure
Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.x - SafeMode Arbitrary File Execution
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows lo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xinetd 2.1.8 - Remote Buffer Overflow
Buffer overflow in Linux xinetd 2.1.8.9pre11-1 and earlier may allow remote attackers to execute arbitrary code via a lo
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.