Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
24.460 exploits
Exploit-DB✓ VexDay Proof
Microsoft IIS 4 (Windows NT) - Remote Web-Based Administration
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 12.0.2 - Syslog Crash
Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Zero Administration Kit (ZAK) 1.0 / Office97 - Backdoor Access
ZAK in Appstation mode allows users to bypass the "Run only allowed apps" policy by starting Explorer from Office 97 app
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Solaris 7.0 - 'ff.core' Local Privilege Escalation
Solaris ff.core allows local users to modify files.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DataLynx suGuard 1.0 - Local Privilege Escalation
DataLynx suGuard trusts the PATH environment variable to execute the ps command, allowing local users to execute command
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Stanford University bootpd 2.4.3 / Debian 2.0 - netstd
Buffer overflow in the FTP client in the Debian GNU/Linux netstd package.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SSH - User Code Execution (Metasploit)
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 7.0 - 'ufsdump' Local Buffer Overflow (2)
Solaris ufsrestore buffer overflow.
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SCO UNIX 5 calserver - Remote Buffer Overflow
Buffer overflow in calserver in SCO OpenServer allows remote attackers to gain root access via a long message.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BNC 2.2.4/2.4.6/2.4.8 - IRC Proxy Buffer Overflow (2)
Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BNC 2.2.4/2.4.6/2.4.8 - IRC Proxy Buffer Overflow (1)
Buffer overflow in BNC IRC proxy allows remote attackers to gain privileges.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Allaire ColdFusion Server 4.0 - Remote File Display / Deletion / Upload / Execution
The Expression Evaluator sample application in ColdFusion allows remote attackers to read or delete files on the server
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Allaire ColdFusion Server 4.0 - Remote File Display / Deletion / Upload / Execution
The Expression Evaluator in the ColdFusion Application Server allows a remote attacker to upload files to the server via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.5.1 - 'kcms' Local Buffer Overflow (2)
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.5.1 - 'kcms' Local Buffer Overflow (1)
Buffer overflow in Solaris kcms_configure command allows local users to gain root access.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Greg Matthews - 'Classifieds.cgi' 1.0 Hidden Variable
classifieds.cgi allows remote attackers to execute arbitrary commands by specifying them in a hidden variable in a CGI f
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Greg Matthews - 'Classifieds.cgi' 1.0 MetaCharacter
classifieds.cgi allows remote attackers to read arbitrary files via shell metacharacters.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sendmail 8.9.2 - Headers Prescan Denial of Service
Remote attackers can cause a denial of service in Sendmail 8.8.x and 8.9.2 by sending messages with a large number of he
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SCO Unixware 7.0/7.0.1/7.1/7.1.1 - 'uidadmin' Local Privilege Escalation
UnixWare uidadmin allows local users to modify arbitrary files via a symlink attack.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Netware Web Server 3.x - files.pl
Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.3 - 'infod' Local Privilege Escalation
AIX infod allows local users to gain root access through an X display.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IRIX 6.2/6.3 - '/bin/lpstat' Local Buffer Overflow
Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Solaris 7.0 - '/usr/dt/bin/sdtcm_convert' Local Overflow / Local Privilege Escalation
The Sun sdtcm_convert calendar utility for OpenWindows has a buffer overflow which can gain root access.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 3/4/5/6 / OpenLinux 1.0/1.1 - routed traceon
Routed allows attackers to append data to files.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.5.1 - License Manager
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 10.x/11.x - Aserver PATH
The October 1998 version of the HP-UX aserver program allows local users to gain privileges by specifying an alternate P
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xi Graphics Maximum CDE 1.2.3/TriTeal TED CDE 4.3/Sun Solaris 2.5.1 - ToolTalk RPC Service Overflow (1)
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xi Graphics Maximum CDE 1.2.3/TriTeal TED CDE 4.3/Sun Solaris 2.5.1 - ToolTalk RPC Service Overflow (2)
Execute commands as root via buffer overflow in Tooltalk database server (rpc.ttdbserverd).
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 5.1 / Caldera OpenLinux Standard 1.2 - Mountd
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape Enterprise Server 3.x/4.x - PageServices Information Disclosure
Netscape Enterprise servers may list files through the PageServices query.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.