Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8195Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
20.023 exploits
Referência
CVE-2018-6383
Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but
28RIESGO
abrir ↗Referência
CVE-2018-7739
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and
35RIESGO
abrir ↗Referência
CVE-2015-6589
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before
28RIESGO
abrir ↗Referência
CVE-2015-6589
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.0.0.0 before 7.0.0.33, 8..0.0.0 before
28RIESGO
abrir ↗Referência
CVE-2014-5465
Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress
28RIESGO
abrir ↗Referência
eXtremail 2.1.1 - 'memmove()' Remote Denial of Service
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execu
28RIESGO
abrir ↗Referência
GuildFTPd 0.999.8.11/0.999.14 - Heap Corruption (PoC) / Denial of Service
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir ↗Referência
CVE-2011-0421
The _zip_name_locate function in zip_name_locate.c in the Zip extension in PHP before 5.3.6 does not properly handle a Z
28RIESGO
abrir ↗Referência
Sun Solaris 10 - snoop(1M) Utility Remote Command Execution
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o op
28RIESGO
abrir ↗Referência
CVE-2019-3010
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir ↗Referência
CVE-2017-6444
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast netw
28RIESGO
abrir ↗Referência
CVE-2017-6444
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast netw
28RIESGO
abrir ↗Referência
CVE-2021-25159
A remote arbitrary file modification vulnerability was discovered in some Aruba Instant Access Point (IAP) products in v
28RIESGO
abrir ↗Referência
CVE-2009-4491
thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers
53RIESGO
abrir ↗Referência
Windows 10.0.17763.7009 - spoofing vulnerability
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir ↗Referência
iPrimal Forums - '/admin/index.php' Remote File Inclusion
PHP remote file inclusion vulnerability in (1) index.php and (2) admin/index.php in IPrimal Forums as of 20061105 allows
23RIESGO
abrir ↗Referência
VideoLAN VLC Media Player 0.8.6i - '.tta' File Parsing Heap Overflow (PoC)
Integer overflow in the Open function in modules/demux/tta.c in VLC Media Player 0.8.6i allows remote attackers to cause
28RIESGO
abrir ↗Referência
CVE-2019-17424
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RIESGO
abrir ↗Referência
windows 10/11 - NTLM Hash Disclosure Spoofing
NTLM Hash Disclosure Spoofing Vulnerability
75RIESGO
abrir ↗Referência
CVE-2016-2278
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows
28RIESGO
abrir ↗Referência
CVE-2018-8056
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/ma
28RIESGO
abrir ↗Referência
CVE-2015-1365
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows rem
28RIESGO
abrir ↗Referência
CVE-2018-7739
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and
35RIESGO
abrir ↗Referência
CVE-2015-1365
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows rem
28RIESGO
abrir ↗Referência
CVE-2021-25681
AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. T
28RIESGO
abrir ↗Referência
CVE-2019-10863
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows on
28RIESGO
abrir ↗Referência
TeemIp IPAM < 2.4.0 - 'new_config' Command Injection (Metasploit)
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows on
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.