Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
Wordpress XMLRPC DoS
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, doe
23RIESGO
abrir ↗Metasploit0
HybridAuth install.php PHP Code Execution
HybridAuth 2.0.9 - 2.2.2 Unauthenticated RCE via install.php Configuration Injection
63RIESGO
abrir ↗Metasploit600
Dell SonicWALL Scrutinizer 11.01 methodDetail SQL Injection
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RIESGO
abrir ↗Metasploit200
MQAC.sys Arbitrary Write Privilege Escalation
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir ↗Metasploit200
MS14-062 Microsoft Bluetooth Personal Area Networking (BthPan.sys) Privilege Escalation
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir ↗Metasploit300
Advantech WebAccess dvs.ocx GetColor Buffer Overflow
Advantech WebAccess Stack-Based Buffer Overflow
68RIESGO
abrir ↗Metasploit200
VirtualBox Guest Additions VBoxGuest.sys Privilege Escalation
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 3.2.24, 4.0.2
38RIESGO
abrir ↗Metasploit300
Flash "Rosetta" JSONP GET/POST Response Disclosure
Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Ad
23RIESGO
abrir ↗Metasploit600
Wordpress MailPoet Newsletters (wysija-newsletters) Unauthenticated File Upload
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authen
50RIESGO
abrir ↗Metasploit600
Gitlist Unauthenticated Remote Command Execution
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RIESGO
abrir ↗Metasploit600
VMTurbo Operations Manager vmtadmin.cgi Remote Command Execution
vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands
60RIESGO
abrir ↗Metasploit600
Wing FTP Server Authenticated Command Execution
In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection o
100RIESGO
abrir ↗Metasploit600
ManageEngine Desktop Central / Password Manager LinkViewFetchServlet.dat SQL Injection
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central
50RIESGO
abrir ↗Metasploit300
OpenSSL DTLS Fragment Buffer Overflow DoS
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0
40RIESGO
abrir ↗Metasploit300
OpenSSL Server-Side ChangeCipherSpec Injection Scanner
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCiph
60RIESGO
abrir ↗Metasploit0
Chkrootkit Local Privilege Escalation
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RIESGO
abrir ↗Metasploit300
Ericom AccessNow Server Buffer Overflow
Stack-based buffer overflow in AccessServer32.exe in Ericom AccessNow Server allows remote attackers to execute arbitrar
50RIESGO
abrir ↗Metasploit300
Yokogawa CS3000 BKFSim_vhfd.exe Buffer Overflow
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V
50RIESGO
abrir ↗Metasploit300
D-Link info.cgi POST Request Buffer Overflow
D-Link info.cgi POST Request Stack-Based Buffer Overflow RCE
63RIESGO
abrir ↗Metasploit300
Easy File Management Web Server Stack Buffer Overflow
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code
60RIESGO
abrir ↗Metasploit300
D-Link HNAP Request Remote Buffer Overflow
Stack-based buffer overflow in the do_hnap function in www/my_cgi.cgi in D-Link DSP-W215 (Rev. A1) with firmware 1.01b06
60RIESGO
abrir ↗Metasploit600
Symantec Workspace Streaming ManagementAgentServer.putFile XMLRPC Request Arbitrary File Upload
The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functional
50RIESGO
abrir ↗Metasploit300
Belkin Play N750 login.cgi Buffer Overflow
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RIESGO
abrir ↗Metasploit300
AlienVault Authenticated SQL Injection Arbitrary File Read
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL
43RIESGO
abrir ↗Metasploit600
AlienVault OSSIM av-centerd Command Injection
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a
60RIESGO
abrir ↗Metasploit600
Android 'Towelroot' Futex Requeue Kernel Exploit
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗Metasploit0
Cogent DataHub Command Injection
GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary
50RIESGO
abrir ↗Metasploit300
Wireshark CAPWAP Dissector DoS
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.
50RIESGO
abrir ↗Metasploit500
Adobe Flash Player Shader Buffer Overflow
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.