Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit500
Adobe Flash Player Shader Buffer Overflow
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS
60RIESGO
abrir ↗Metasploit600
AlienVault OSSIM SQL Injection and Remote Code Execution
A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5
43RIESGO
abrir ↗Metasploit600
Oracle Event Processing FileUploadServlet Arbitrary File Upload
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote
50RIESGO
abrir ↗Metasploit500
Adobe Flash Player domainMemory ByteArray Use After Free
Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and
60RIESGO
abrir ↗Metasploit400
Adobe Reader for Android addJavascriptInterface Exploit
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows r
60RIESGO
abrir ↗Metasploit300
Cisco ASA SSL VPN Privilege Escalation Vulnerability
Cisco Adaptive Security Appliance (ASA) Software 8.x before 8.2(5.48), 8.3 before 8.3(2.40), 8.4 before 8.4(7.9), 8.6 be
23RIESGO
abrir ↗Metasploit600
Sophos Web Protection Appliance Interface Authenticated Arbitrary Command Execution
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users
50RIESGO
abrir ↗Metasploit600
Sophos Web Protection Appliance Interface Authenticated Arbitrary Command Execution
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RIESGO
abrir ↗Metasploit300
Advantech WebAccess DBVisitor.dll ChartThemeConfig SQL Injection
Advantech WebAccess SQL Injection
41RIESGO
abrir ↗Metasploit300
OpenSSL Heartbeat (Heartbleed) Information Leak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Metasploit300
OpenSSL Heartbeat (Heartbleed) Client Memory Exposure
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Metasploit600
Belkin Wemo UPnP Remote Code Execution
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetS
40RIESGO
abrir ↗Metasploit600
eScan Web Management Console Command Injection
eScan 5.5-2 Web Management Console Command Injection
63RIESGO
abrir ↗Metasploit300
MS14-017 Microsoft Word RTF Object Confusion
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi
100RIESGO
abrir ↗Metasploit300
EMC CTA v10.0 Unauthenticated XXE Arbitrary File Read
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login reques
50RIESGO
abrir ↗Metasploit300
AlienVault Authenticated SQL Injection Arbitrary File Read
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier
43RIESGO
abrir ↗Metasploit300
Katello (Red Hat Satellite) users/update_roles Missing Authorization
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update
50RIESGO
abrir ↗Metasploit600
FreePBX config.php Remote Code Execution
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12
50RIESGO
abrir ↗Metasploit400
Wireshark wiretap/mpeg.c Stack Buffer Overflow
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10
50RIESGO
abrir ↗Metasploit600
SePortal SQLi Remote Code Execution
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RIESGO
abrir ↗Metasploit600
Firefox WebIDL Privileged Javascript Injection
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remo
60RIESGO
abrir ↗Metasploit600
Firefox WebIDL Privileged Javascript Injection
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and Se
60RIESGO
abrir ↗Metasploit200
VirtualBox 3D Acceleration Virtual Machine Escape
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/s
38RIESGO
abrir ↗Metasploit300
MS14-012 Microsoft Internet Explorer TextRange Use-After-Free
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause
60RIESGO
abrir ↗Metasploit200
Yokogawa CENTUM CS 3000 BKHOdeq.exe Buffer Overflow
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
75RIESGO
abrir ↗Metasploit300
Yokogawa CS3000 BKESimmgr.exe Buffer Overflow
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
68RIESGO
abrir ↗Metasploit300
Yokogawa CENTUM CS 3000 BKBCopyD.exe Buffer Overflow
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
68RIESGO
abrir ↗Metasploit300
Yokogawa CENTUM CS 3000 BKCLogSvr.exe Heap Buffer Overflow
Yokogawa CENTUM CS 3000 Heap-based Buffer Overflow
48RIESGO
abrir ↗Metasploit600
ifwatchd Privilege Escalation
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arb
38RIESGO
abrir ↗Metasploit300
GetGo Download Manager HTTP Response Buffer Overflow
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attac
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.