Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
3462 exploits
Metasploit300
Cisco IOS HTTP GET /%% Request Denial of Service
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a deni
50RIESGO
abrir ↗Metasploit300
OpenSSL DTLS ChangeCipherSpec Remote DoS
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and
60RIESGO
abrir ↗Metasploit400
UoW IMAP Server LSUB Buffer Overflow
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RIESGO
abrir ↗Metasploit600
RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution
The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary command
50RIESGO
abrir ↗Metasploit600
RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password tha
60RIESGO
abrir ↗Metasploit300
ARP Spoof
The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denia
23RIESGO
abrir ↗Metasploit600
Matt Wright guestbook.pl Arbitrary Command Execution
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remo
60RIESGO
abrir ↗Metasploit0
SSH User Code Execution
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit600
Windows Management Instrumentation (WMI) Remote Command Execution
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit600
Powershell Remoting Remote Command Execution
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit0
Microsoft Windows Authenticated User Code Execution
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit600
PsExec via Current User Token
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit600
MS99-025 Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x expose
60RIESGO
abrir ↗Metasploit200
War-FTPD 1.65 Username Overflow
Buffer overflow in War FTP allows remote execution of commands.
60RIESGO
abrir ↗Metasploit200
War-FTPD 1.65 Password Overflow
Buffer overflow in War FTP allows remote execution of commands.
60RIESGO
abrir ↗Metasploit300
X11 Keylogger
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
23RIESGO
abrir ↗Metasploit300
Chargen Probe Utility
Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or U
23RIESGO
abrir ↗Metasploit600
Solaris ypupdated Command Execution
The SunView (SunTools) selection_svc facility allows remote users to read files.
50RIESGO
abrir ↗Metasploit300
Brocade Enable Login Check Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
Memcached Remote Denial of Service
Multiple integer signedness errors in the (1) process_bin_sasl_auth, (2) process_bin_complete_sasl_auth, (3) process_bin
23RIESGO
abrir ↗Metasploit300
Cambium ePMP 1000 'get_chart' Command Injection (v3.1-3.5-RC7)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RIESGO
abrir ↗Metasploit300
ws - Denial of Service
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date
18RIESGO
abrir ↗Metasploit300
WordPress Traversal Directory DoS
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RIESGO
abrir ↗Metasploit300
ua-parser-js npm module ReDoS
ua-parser is a port of Browserscope's user agent parser. ua-parser is vulnerable to a ReDoS (Regular Expression Denial o
18RIESGO
abrir ↗Metasploit300
Tautulli v2.1.9 - Shutdown Denial of Service
In Tautulli 2.1.9, CSRF in the /shutdown URI allows an attacker to shut down the remote media server. (Also, anonymous a
23RIESGO
abrir ↗Metasploit300
Cambium ePMP 1000 'ping' Command Injection (up to v2.5)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RIESGO
abrir ↗Metasploit300
MS15-034 HTTP Protocol Stack Request Handling Denial-of-Service
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗Metasploit300
Cambium ePMP 1000 Account Password Reset
In version 3.5 and prior of Cambium Networks ePMP firmware, the non-administrative users 'installer' and 'home' have the
30RIESGO
abrir ↗Metasploit300
FortiMail Unauthenticated Login Bypass Scanner
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 an
40RIESGO
abrir ↗Metasploit300
Carlo Gavazzi Energy Meters - Login Brute Force, Extract Info and Dump Plant Database
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Vers
18RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.