Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
Allegro Software RomPager 'Misfortune Cookie' (CVE-2014-9222) Authentication Bypass
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows re
30RIESGO
abrir ↗Metasploit400
Malwarebytes Anti-Malware and Anti-Exploit Update Remote Code Execution
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RIESGO
abrir ↗Metasploit600
Symantec Web Gateway 5 restore.php Post Authentication Command Injection
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RIESGO
abrir ↗Metasploit600
ManageEngine Multiple Products Authenticated File Upload
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RIESGO
abrir ↗Metasploit600
WordPress WP Symposium 14.11 Shell Upload
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RIESGO
abrir ↗Metasploit600
Lexmark MarkVision Enterprise Arbitrary File Upload
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo
60RIESGO
abrir ↗Metasploit300
BMC TrackIt! Unauthenticated Arbitrary User Password Change
BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose na
23RIESGO
abrir ↗Metasploit600
ProjectSend Arbitrary File Upload
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RIESGO
abrir ↗Metasploit300
ManageEngine NetFlow Analyzer Arbitrary File Download
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 a
60RIESGO
abrir ↗Metasploit600
Tuleap PHP Unserialize Code Execution
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated
43RIESGO
abrir ↗Metasploit600
WordPress RevSlider File Upload and Execute Vulnerability
The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier
60RIESGO
abrir ↗Metasploit300
Adobe Flash Player PCRE Regex Vulnerability
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RIESGO
abrir ↗Metasploit300
Arris VAP2500 tools_command.php Command Execution
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute ar
50RIESGO
abrir ↗Metasploit300
Arris VAP2500 tools_command.php Command Execution
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authenticatio
50RIESGO
abrir ↗Metasploit300
WordPress Long Password DoS
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RIESGO
abrir ↗Metasploit300
Hikvision DVR RTSP Request Remote Code Execution
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RIESGO
abrir ↗Metasploit500
HP Performance Monitoring xglance Priv Esc
Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via u
38RIESGO
abrir ↗Metasploit300
MS14-068 Microsoft Kerberos Checksum Validation Vulnerability
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008
100RIESGO
abrir ↗Metasploit300
Cisco DLSw Information Disclosure Scanner
The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensiti
23RIESGO
abrir ↗Metasploit400
MS14-064 Microsoft Internet Explorer Windows OLE Automation Array Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Metasploit600
MS14-064 Microsoft Windows OLE Package Manager Code Execution Through Python
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir ↗Metasploit400
Adobe Flash Player UncompressViaZlibVariant Uninitialized Memory
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on
60RIESGO
abrir ↗Metasploit600
WordPress Photo Gallery Unrestricted File Upload
Unrestricted File Upload vulnerability in Photo Gallery 1.2.5.
50RIESGO
abrir ↗Metasploit200
MS14-070 Windows tcpip!SetAddrOptions NULL Pointer Dereference
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir ↗Metasploit500
MantisBT XmlImportExport Plugin PHP Code Injection Vulnerability
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RIESGO
abrir ↗Metasploit300
ManageEngine Password Manager SQLAdvancedALSearchResult.cc Pro SQL Injection
Multiple SQL injection vulnerabilities in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Servi
50RIESGO
abrir ↗Metasploit500
MantisBT XmlImportExport Plugin PHP Code Injection Vulnerability
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb
50RIESGO
abrir ↗Metasploit300
i-FTP Schedule Buffer Overflow
i-Ftp 2.20 Schedule.xml Stack-Based Buffer Overflow
36RIESGO
abrir ↗Metasploit300
ManageEngine Eventlog Analyzer Managed Hosts Administrator Credential Disclosure
ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed versio
50RIESGO
abrir ↗Metasploit300
ManageEngine Eventlog Analyzer Managed Hosts Administrator Credential Disclosure
Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerabili
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.