Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
ProFTPD 1.3.5 Mod_Copy Command Execution
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir ↗Metasploit600
GoAutoDial 3.3 Authentication Bypass / Command Injection
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arb
60RIESGO
abrir ↗Metasploit600
GoAutoDial 3.3 Authentication Bypass / Command Injection
Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute
50RIESGO
abrir ↗Metasploit600
ABRT raceabrt Privilege Escalation
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac
38RIESGO
abrir ↗Metasploit600
Lenovo System Update Privilege Escalation
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allo
38RIESGO
abrir ↗Metasploit600
Wordpress N-Media Website Contact Form Upload Vulnerability
Website Contact Form With File Upload <= 1.3.4 - Arbitrary File Upload
63RIESGO
abrir ↗Metasploit500
Apple OS X Rootpipe Privilege Escalation
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RIESGO
abrir ↗Metasploit300
Archer C7 Directory Traversal Vulnerability
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before
100RIESGO
abrir ↗Metasploit300
Apple OSX/iOS/Windows Safari Non-HTTPOnly Cookie Theft
WebKit, as used in Apple iOS before 8.3 and Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, does not
18RIESGO
abrir ↗Metasploit600
Novell ZENworks Configuration Management Arbitrary File Upload
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11
60RIESGO
abrir ↗Metasploit600
Ceragon FibeAir IP-10 SSH Private Key Exposure
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RIESGO
abrir ↗Metasploit600
Apport / ABRT chroot Privilege Escalation
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RIESGO
abrir ↗Metasploit0
Firefox PDF.js Privileged Javascript Injection
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource
50RIESGO
abrir ↗Metasploit300
Airties login-cgi Buffer Overflow
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RIESGO
abrir ↗Metasploit0
Firefox PDF.js Privileged Javascript Injection
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RIESGO
abrir ↗Metasploit300
Web-Dorado ECommerce WD for Joomla! search_category_id SQL Injection Scanner
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allo
50RIESGO
abrir ↗Metasploit600
Wordpress Work The Flow Upload Vulnerability
Work The Flow File Upload <= 2.5.2 - Arbitrary File Upload
63RIESGO
abrir ↗Metasploit600
Solarwinds Firewall Security Manager 6.6.5 Client Session Handling Vulnerability
userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privile
60RIESGO
abrir ↗Metasploit500
Adobe Flash Player NetConnection Type Confusion
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451
60RIESGO
abrir ↗Metasploit600
iPass Mobile Client Service Privilege Escalation
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RIESGO
abrir ↗Metasploit600
Microsoft Windows Shell LNK Code Execution
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
60RIESGO
abrir ↗Metasploit600
Microsoft Windows Shell LNK Code Execution
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
60RIESGO
abrir ↗Metasploit600
WordPress WPshop eCommerce Arbitrary File Upload Vulnerability
WPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File Upload
43RIESGO
abrir ↗Metasploit600
PHPMoAdmin 1.1.2 Remote Code Execution
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RIESGO
abrir ↗Metasploit300
WordPress CP Multi-View Calendar Unauthenticated SQL Injection Scanner
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RIESGO
abrir ↗Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir ↗Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RIESGO
abrir ↗Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RIESGO
abrir ↗Metasploit300
D-Link/TRENDnet NCC Service Command Injection
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RIESGO
abrir ↗Metasploit300
WordPress WP EasyCart Plugin Privilege Escalation
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyC
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.