Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
Logsign Remote Command Injection
Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability
36RIESGO
abrir ↗Metasploit600
Netgear DGN2200 dnslookup.cgi Command Injection
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RIESGO
abrir ↗Metasploit300
Kodi 17.0 Local File Inclusion Vulnerability
Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files v
40RIESGO
abrir ↗Metasploit600
Piwik Superuser Plugin Upload
Piwik Authenticated RCE via Custom Plugin Upload
43RIESGO
abrir ↗Metasploit300
Postfixadmin Protected Alias Deletion Vulnerability
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected al
23RIESGO
abrir ↗Metasploit300
WordPress REST API Content Injection
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in Wor
40RIESGO
abrir ↗Metasploit600
AlienVault OSSIM/USM Remote Code Execution
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbit
50RIESGO
abrir ↗Metasploit600
Haraka SMTP Command Injection
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlie
23RIESGO
abrir ↗Metasploit600
Oracle Weblogic Server Deserialization RCE - RMI UnicastRef
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir ↗Metasploit300
Geutebrueck GCore - GCoreServer.exe Buffer Overflow RCE
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RIESGO
abrir ↗Metasploit500
Cisco WebEx Chrome Extension RCE (CVE-2017-3823)
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Conta
23RIESGO
abrir ↗Metasploit300
Advantech WebAccess 8.1 Post Authentication Credential Collector
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive
23RIESGO
abrir ↗Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
An issue was discovered in Trend Micro InterScan Messaging Security (Virtual Appliance) 9.1-1600. An authenticated user
30RIESGO
abrir ↗Metasploit400
Debian/Ubuntu ntfs-3g Local Privilege Escalation
ntfs-3g: Modprobe influence vulnerability via environment variables
56RIESGO
abrir ↗Metasploit0
PHPMailer Sendmail Argument Injection
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Metasploit600
TrueOnline / ZyXEL P660HN-T v2 Router Authenticated Command Injection
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has three user accounts with default passw
23RIESGO
abrir ↗Metasploit0
PHPMailer Sendmail Argument Injection
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RIESGO
abrir ↗Metasploit600
TrueOnline / ZyXEL P660HN-T v2 Router Authenticated Command Injection
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in t
23RIESGO
abrir ↗Metasploit600
TrueOnline / Billion 5200W-T Router Unauthenticated Command Injection
The Billion 5200W-T 1.02b.rc5.dt49 router distributed by TrueOnline has a command injection vulnerability in the Remote
30RIESGO
abrir ↗Metasploit600
TrueOnline / Billion 5200W-T Router Unauthenticated Command Injection
The Billion 5200W-T TCLinux Fw $7.3.8.0 v008 130603 router distributed by TrueOnline has a command injection vulnerabili
23RIESGO
abrir ↗Metasploit600
TrueOnline / ZyXEL P660HN-T v1 Router Unauthenticated Command Injection
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command inject
100RIESGO
abrir ↗Metasploit600
VMware VDP Known SSH Key
VMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which mak
30RIESGO
abrir ↗Metasploit300
NETGEAR WNR2000v5 Administrator Password Recovery
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. Thi
50RIESGO
abrir ↗Metasploit600
NETGEAR WNR2000v5 (Un)authenticated hidden_lang_avi Stack Buffer Overflow
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RIESGO
abrir ↗Metasploit300
NETGEAR WNR2000v5 Administrator Password Recovery
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the w
60RIESGO
abrir ↗Metasploit600
Western Digital MyCloud unauthenticated command injection
It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulne
40RIESGO
abrir ↗Metasploit600
Western Digital MyCloud unauthenticated command injection
Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytic
40RIESGO
abrir ↗Metasploit600
Netgear R7000 and R6400 cgi-bin Command Injection
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RIESGO
abrir ↗Metasploit600
DiskBoss Enterprise GET Buffer Overflow
DiskBoss Enterprise Stack-Based Buffer Overflow RCE
43RIESGO
abrir ↗Metasploit600
DiskSavvy Enterprise GET Buffer Overflow
Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary c
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.