Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
3462 exploits
Metasploit400
Apache Win32 Chunked Encoding
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possi
60RIESGO
abrir ↗Metasploit400
Oracle 8i TNS Listener SERVICE_NAME Buffer Overflow
Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users
50RIESGO
abrir ↗Metasploit400
MS02-018 Microsoft IIS 4.0 .HTR Path Overflow
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .
60RIESGO
abrir ↗Metasploit600
DistCC Daemon Command Execution
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RIESGO
abrir ↗Metasploit600
Solaris in.telnetd TTYPROMPT Buffer Overflow
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RIESGO
abrir ↗Metasploit400
System V Derived /bin/login Extraneous Arguments Buffer Overflow
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RIESGO
abrir ↗Metasploit600
Irix LPD tagprinter Command Execution
lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.
50RIESGO
abrir ↗Metasploit600
Solaris LPD Command Execution
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request wit
60RIESGO
abrir ↗Metasploit400
Network Associates PGP KeyServer 7 LDAP Buffer Overflow
Network Associates PGP Keyserver 7.0 allows remote attackers to cause a denial of service (crash) and possibly execute a
50RIESGO
abrir ↗Metasploit400
Oracle 8i TNS Listener (ARGUMENTS) Buffer Overflow
Buffer overflow in Transparent Network Substrate (TNS) Listener in Oracle 8i 8.1.7 and earlier allows remote attackers t
60RIESGO
abrir ↗Metasploit300
Cisco IOS HTTP Unauthorized Administrative Access
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RIESGO
abrir ↗Metasploit400
MS01-033 Microsoft IIS 5.0 IDQ Path Overflow
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RIESGO
abrir ↗Metasploit600
MS01-026 Microsoft IIS/PWS CGI Filename Double Decode Command Execution
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RIESGO
abrir ↗Metasploit400
MS01-023 Microsoft IIS 5.0 Printer Host Header Overflow
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via
60RIESGO
abrir ↗Metasploit400
NTP Daemon readvar Buffer Overflow
Buffer overflow in ntpd ntp daemon 4.0.99k and earlier (aka xntpd and xntp3) allows remote attackers to cause a denial o
60RIESGO
abrir ↗Metasploit600
MS08-068 Microsoft Windows SMB Relay Code Execution
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 20
50RIESGO
abrir ↗Metasploit300
Windows Gather DynaZIP Saved Password Extraction
The password protection option for the Compressed Folders feature in Plus! for Windows 98 and Windows Me writes password
18RIESGO
abrir ↗Metasploit600
HP OpenView OmniBack II Command Execution
Vulnerability in OmniBackII A.03.50 in HP 11.x and earlier allows attackers to gain unauthorized access to an OmniBack c
43RIESGO
abrir ↗Metasploit300
RealVNC 3.3.7 Client Buffer Overflow
Buffer overflow in AT&T WinVNC (Virtual Network Computing) client 3.3.3r7 and earlier allows remote attackers to execute
50RIESGO
abrir ↗Metasploit200
WinVNC Web Server GET Overflow
Buffer overflow in AT&T WinVNC (Virtual Network Computing) server 3.3.3r7 and earlier allows remote attackers to execute
60RIESGO
abrir ↗Metasploit400
MS00-094 Microsoft IIS Phone Book Service Overflow
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Se
60RIESGO
abrir ↗Metasploit300
Cisco Device HTTP Device Manager Access
The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands with
60RIESGO
abrir ↗Metasploit300
LPRng use_syslog Remote Format String Vulnerability
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary comman
60RIESGO
abrir ↗Metasploit200
GAMSoft TelSrv 1.5 Username Buffer Overflow
GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.
50RIESGO
abrir ↗Metasploit300
UoW pop2d Remote File Retrieval Vulnerability
Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD com
50RIESGO
abrir ↗Metasploit500
WU-FTPD SITE EXEC/INDEX Format String Vulnerability
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RIESGO
abrir ↗Metasploit600
Microsoft SQL Server Payload Execution via SQL Injection
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3)
60RIESGO
abrir ↗Metasploit600
Microsoft SQL Server Payload Execution via SQL Injection
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in pla
60RIESGO
abrir ↗Metasploit600
Microsoft SQL Server Payload Execution
The "sa" account is installed with a default null password on (1) Microsoft SQL Server 2000, (2) SQL Server 7.0, and (3)
60RIESGO
abrir ↗Metasploit600
Microsoft SQL Server Payload Execution
The Mixed Mode authentication capability in Microsoft SQL Server 7.0 stores the System Administrator (sa) account in pla
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.