Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
WordPress Contus Video Gallery Unauthenticated SQL Injection Scanner
SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b
50RIESGO
abrir ↗Metasploit300
Solarwinds Orion AccountManagement.asmx GetAccounts Admin Creation
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RIESGO
abrir ↗Metasploit500
D-Link DCS-931L File Upload
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use
50RIESGO
abrir ↗Metasploit300
D-Link Devices HNAP SOAPAction-Header Command Execution
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute ar
100RIESGO
abrir ↗Metasploit600
Maarch LetterBox Unrestricted File Upload
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earl
50RIESGO
abrir ↗Metasploit400
SixApart MovableType Storable Perl Code Execution
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use
60RIESGO
abrir ↗Metasploit600
ElasticSearch Search Groovy Sandbox Bypass
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir ↗Metasploit600
WordPress Holding Pattern Theme Arbitrary File Upload
Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 a
50RIESGO
abrir ↗Metasploit300
WordPress WPLMS Theme Privilege Escalation
WPLMS Learning Management System for WordPress, WordPress LMS <= 1.8.4.1 - Privilege Escalation
36RIESGO
abrir ↗Metasploit600
Ektron 8.5, 8.7, 9.0 XSLT Transform Remote Code Execution
The ContentBlockEx method in Workarea/ServerControlWS.asmx in Ektron Content Management System (CMS) 8.5 and 8.7 before
23RIESGO
abrir ↗Metasploit500
Adobe Flash Player ByteArray With Workers Use After Free
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir ↗Metasploit300
MS15-018 Microsoft Internet Explorer 10 and 11 Cross-Domain JavaScript Injection
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass t
60RIESGO
abrir ↗Metasploit300
X360 VideoPlayer ActiveX Control Buffer Overflow
X360 VideoPlayer ActiveX Control Buffer Overflow via ConvertFile()
36RIESGO
abrir ↗Metasploit300
ManageEngine Multiple Products Arbitrary File Download
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, O
60RIESGO
abrir ↗Metasploit300
ManageEngine Multiple Products Arbitrary Directory Listing
The FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine Applications Manager before 11.9 build 11912, O
60RIESGO
abrir ↗Metasploit600
Oracle Weblogic Server Deserialization RCE - Raw Object
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir ↗Metasploit500
Exim GHOST (glibc gethostbyname) Buffer Overflow
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir ↗Metasploit600
IPass Control Pipe Remote Command Execution
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RIESGO
abrir ↗Metasploit600
WordPress Platform Theme File Upload Vulnerability
Platform < 1.4.4 - Missing Authorization to Unauthenticated Arbitrary Options Update
43RIESGO
abrir ↗Metasploit300
Java Secure Socket Extension (JSSE) SKIP-TLS MITM Proxy
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.
50RIESGO
abrir ↗Metasploit600
WordPress Pixabay Images PHP Code Upload
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot
50RIESGO
abrir ↗Metasploit400
MS15-004 Microsoft Remote Desktop Services Web Proxy IE Sandbox Escape
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir ↗Metasploit600
WordPress WP EasyCart Unrestricted File Upload
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RIESGO
abrir ↗Metasploit300
McAfee ePolicy Orchestrator Authenticated XXE Credentials Exposure
XML external entity (XXE) vulnerability in the Server Task Log in McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x
23RIESGO
abrir ↗Metasploit300
McAfee ePolicy Orchestrator Authenticated XXE Credentials Exposure
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers'
23RIESGO
abrir ↗Metasploit600
ASUS infosvr Auth Bypass Command Execution
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RIESGO
abrir ↗Metasploit300
ManageEngine Desktop Central Administrator Account Creation
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at
60RIESGO
abrir ↗Metasploit300
Achat Unicode SEH Buffer Overflow
Achat v0.150 SEH Buffer Overflow via UDP
63RIESGO
abrir ↗Metasploit600
Malicious Git and Mercurial HTTP Server For CVE-2014-9390
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS
40RIESGO
abrir ↗Metasploit300
Allegro Software RomPager 'Misfortune Cookie' (CVE-2014-9222) Scanner
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows re
30RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.