Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
MS15-134 Microsoft Windows Media Center MCL Information Disclosure
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows remote attackers t
50RIESGO
abrir ↗Metasploit300
Office OLE Multiple DLL Side Loading Vulnerabilities
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
60RIESGO
abrir ↗Metasploit300
Windows WMI Receive Notification Exploit
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir ↗Metasploit300
Easy File Sharing HTTP Server 7.2 SEH Overflow
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir ↗Metasploit600
Advantech Switch Bash Environment Variable Code Injection (Shellshock)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit600
Cambium ePMP1000 'ping' Shell via Command Injection (up to v2.5)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RIESGO
abrir ↗Metasploit600
ABRT sosreport Privilege Escalation
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
38RIESGO
abrir ↗Metasploit600
Jenkins CLI RMI Java Deserialization Vulnerability
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RIESGO
abrir ↗Metasploit600
IBM WebSphere RCE Java Deserialization Vulnerability
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RIESGO
abrir ↗Metasploit300
OpenNMS Java Object Unserialization Remote Code Execution
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RIESGO
abrir ↗Metasploit600
vBulletin 5.1.2 Unserialize Code Execution
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir ↗Metasploit600
Atlassian HipChat for Jira Plugin Velocity Template Injection
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RIESGO
abrir ↗Metasploit600
Joomla Content History SQLi Remote Code Execution
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir ↗Metasploit600
Joomla Content History SQLi Remote Code Execution
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir ↗Metasploit600
Joomla Content History SQLi Remote Code Execution
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir ↗Metasploit300
Joomla com_contenthistory Error-Based SQL Injection
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir ↗Metasploit0
Safari User-Assisted Applescript Exec Attack
Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement f
50RIESGO
abrir ↗Metasploit300
Limesurvey Unauthenticated File Download
LimeSurvey 2.0+ - 2.06+ Unauthenticated Arbitrary File Download via Serialized Backup Payload
36RIESGO
abrir ↗Metasploit600
Wordpress Ajax Load More PHP Upload Vulnerability
Ajax Load More < 2.8.1.2 - Subscriber+ File Upload & Deletion
36RIESGO
abrir ↗Metasploit300
ManageEngine ServiceDesk Plus Path Traversal
Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remot
50RIESGO
abrir ↗Metasploit300
PDF Shaper Buffer Overflow
PDF Shaper v3.5/3.6 Buffer Overflow via Convert to Image Feature
36RIESGO
abrir ↗Metasploit300
Mac OS X 10.9.5 / 10.10.5 - rsh/libmalloc Privilege Escalation
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RIESGO
abrir ↗Metasploit300
Apache James Server 2.3.2 Insecure User Creation Arbitrary File Write
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst
50RIESGO
abrir ↗Metasploit600
Vtiger CRM - Authenticated Logo Upload RCE
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
50RIESGO
abrir ↗Metasploit600
Vtiger CRM - Authenticated Logo Upload RCE
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
43RIESGO
abrir ↗Metasploit300
PCMan FTP Server 2.0.7 Directory Traversal Information Disclosure
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..//
50RIESGO
abrir ↗Metasploit300
BisonWare BisonFTP Server 3.5 Directory Traversal Information Disclosure
Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (d
50RIESGO
abrir ↗Metasploit300
Kaseya VSA Master Administrator Account Creation
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RIESGO
abrir ↗Metasploit600
Kaseya VSA uploader.aspx Arbitrary File Upload
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RIESGO
abrir ↗Metasploit300
Konica Minolta FTP Utility 1.00 Directory Traversal Information Disclosure
Directory traversal vulnerability in Konica Minolta FTP Utility 1.0 allows remote attackers to read arbitrary files via
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.