Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit0
ManageEngine OpManager Remote Code Execution
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser a
50RIESGO
abrir ↗Metasploit0
ManageEngine OpManager Remote Code Execution
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RIESGO
abrir ↗Metasploit600
MS15-100 Microsoft Windows Media Center MCL Vulnerability
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir ↗Metasploit600
F5 iControl iCall::Script Root Command Execution
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir ↗Metasploit600
Nibbleblog File Upload Vulnerability
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir ↗Metasploit300
Boxoft WAV to MP3 Converter v1.1 Buffer Overflow
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RIESGO
abrir ↗Metasploit600
WordPress Responsive Thumbnail Slider Arbitrary File Upload
Responsive Thumbnail Slider < 1.0.1 - Authenticated (Subscriber+) Arbitrary File Upload
36RIESGO
abrir ↗Metasploit600
phpFileManager 0.9.8 Remote Code Execution
phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
23RIESGO
abrir ↗Metasploit600
MVPower DVR Shell Unauthenticated Command Execution
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RIESGO
abrir ↗Metasploit300
Konica Minolta FTP Utility 1.00 Post Auth CWD Command SEH Overflow
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RIESGO
abrir ↗Metasploit600
ManageEngine ServiceDesk Plus Arbitrary File Upload
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via l
98RIESGO
abrir ↗Metasploit600
Apache ActiveMQ 5.x-5.11.1 Directory Traversal Shell Upload
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RIESGO
abrir ↗Metasploit300
WordPress Symposium Plugin SQL Injection
SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi
60RIESGO
abrir ↗Metasploit600
CMS Bolt File Upload Vulnerability
The theme editor in Bolt before 2.2.5 does not check the file extension when renaming files, which allows remote authent
50RIESGO
abrir ↗Metasploit300
Android Stagefright MP4 tx3g Integer Overflow
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir ↗Metasploit300
Path Traversal in Oracle GlassFish Server Open Source Edition
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir ↗Metasploit300
PCMAN FTP Server Buffer Overflow - PUT Command
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗Metasploit600
Hak5 WiFi Pineapple Preconfiguration Command Injection
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir ↗Metasploit600
Hak5 WiFi Pineapple Preconfiguration Command Injection
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir ↗Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RIESGO
abrir ↗Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RIESGO
abrir ↗Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RIESGO
abrir ↗Metasploit300
Heroes of Might and Magic III .h3m Map file Buffer Overflow
Heroes of Might and Magic III .h3m Map File Buffer Overflow
36RIESGO
abrir ↗Metasploit300
Moxa Device Credential Retrieval
An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 52
48RIESGO
abrir ↗Metasploit300
BIND TKEY Query Denial of Service
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗Metasploit500
Libuser roothelper Privilege Escalation
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir ↗Metasploit500
Libuser roothelper Privilege Escalation
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
38RIESGO
abrir ↗Metasploit500
Apple OS X DYLD_PRINT_TO_FILE Privilege Escalation
dyld in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to g
18RIESGO
abrir ↗Metasploit0
ManageEngine EventLog Analyzer Remote Code Execution
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RIESGO
abrir ↗Metasploit0
MS15-078 Microsoft Windows Font Driver Buffer Overflow
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.