Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
Firefox nsSMILTimeContainer::NotifyTimeChange() RCE
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir ↗Metasploit600
Jenkins CLI HTTP Java Deserialization Vulnerability
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a
60RIESGO
abrir ↗Metasploit300
Zyxel/Eir D1000 DSL Modem NewNTPServer Command Injection Over TR-064
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary c
40RIESGO
abrir ↗Metasploit600
Dlink DIR Routers Unauthenticated HNAP Login Stack Buffer Overflow
D-Link DIR routers contain a stack-based buffer overflow in the HNAP Login action
60RIESGO
abrir ↗Metasploit400
WinaXe 7.7 FTP Client Remote Buffer Overflow
WinaXe 7.7 FTP Client Remote Buffer Overflow
36RIESGO
abrir ↗Metasploit600
Bassmaster Batch Arbitrary JavaScript Injection Remote Code Execution
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for t
60RIESGO
abrir ↗Metasploit300
Joomla Account Creation and Privilege Escalation
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RIESGO
abrir ↗Metasploit300
Joomla Account Creation and Privilege Escalation
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RIESGO
abrir ↗Metasploit600
Ruby on Rails Dynamic Render File Upload Remote Code Execution
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RIESGO
abrir ↗Metasploit600
PowerShellEmpire Arbitrary File Upload (Skywalker)
BC Security Empire Path Traversal RCE
68RIESGO
abrir ↗Metasploit300
Cisco Firepower Management Console 6.0 Post Auth Report Download Directory Traversal
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via
50RIESGO
abrir ↗Metasploit600
Cisco Firepower Management Console 6.0 Post Authentication UserAdd Vulnerability
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RIESGO
abrir ↗Metasploit0
Apache Tomcat on RedHat Based Systems Insecure Temp Config Privilege Escalation
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RIESGO
abrir ↗Metasploit600
Disk Pulse Enterprise Login Buffer Overflow
Disk Pulse Enterprise 9.0.34 Login Stack Buffer Overflow
36RIESGO
abrir ↗Metasploit0
Apache Tomcat on Ubuntu Log Init Privilege Escalation
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RIESGO
abrir ↗Metasploit300
Cisco IKE Information Disclosure
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RIESGO
abrir ↗Metasploit300
BIND TSIG Query Denial of Service
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RIESGO
abrir ↗Metasploit600
MagniComp SysInfo mcsiwrapper Privilege Escalation
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RIESGO
abrir ↗Metasploit600
BuilderEngine Arbitrary File Upload Vulnerability and execution
BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗Metasploit500
Grandstream GXV31XX 'settimezone' Unauthenticated Command Execution
Grandstream GAC2500 1.0.3.35, GXP2200 1.0.3.27, GVC3202 1.0.3.51, GXV3275 before 1.0.3.219 Beta, and GXV3240 before 1.0.
23RIESGO
abrir ↗Metasploit400
Safari Webkit JIT Exploit for iOS 7.1.2
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RIESGO
abrir ↗Metasploit400
Safari Webkit JIT Exploit for iOS 7.1.2
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
30RIESGO
abrir ↗Metasploit0
WebKit not_number defineProperties UAF
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir ↗Metasploit0
WebKit not_number defineProperties UAF
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir ↗Metasploit0
WebKit not_number defineProperties UAF
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RIESGO
abrir ↗Metasploit400
AF_PACKET chocobo_root Privilege Escalation
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RIESGO
abrir ↗Metasploit300
ColoradoFTP Server 1.3 Build 8 Directory Traversal Information Disclosure
ColoradoFTP Server <= 1.3 Build 8 Path Traversal Information Disclosure
63RIESGO
abrir ↗Metasploit300
Zabbix toggle_ids SQL Injection
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQ
40RIESGO
abrir ↗Metasploit300
Internet Explorer Iframe Sandbox File Name Disclosure Vulnerability
Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the f
30RIESGO
abrir ↗Metasploit600
Trend Micro Smart Protection Server Exec Remote Code Injection
SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330
30RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.