Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit300
ManageEngine Support Center Plus Directory Traversal
Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arb
50RIESGO
abrir ↗Metasploit600
MediaWiki Thumb.php Remote Command Execution
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RIESGO
abrir ↗Metasploit600
SkyBlueCanvas CMS Remote Code Execution
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RIESGO
abrir ↗Metasploit600
Simple E-Document Arbitrary File Upload
Simple E-Document Arbitrary File Upload RCE
63RIESGO
abrir ↗Metasploit600
GE Proficy CIMPLICITY gefebt.exe Remote Code Execution
GE Proficy HMI/SCADA Path Traversal
78RIESGO
abrir ↗Metasploit0
Firefox Proxy Prototype Privileged Javascript Injection
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RIESGO
abrir ↗Metasploit0
Firefox Proxy Prototype Privileged Javascript Injection
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RIESGO
abrir ↗Metasploit300
Mac OS X Safari file:// Redirection Sandbox Escape
The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allo
23RIESGO
abrir ↗Metasploit500
Oracle Forms and Reports Remote Code Execution
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir ↗Metasploit500
Oracle Forms and Reports Remote Code Execution
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RIESGO
abrir ↗Metasploit400
KingScada kxClientDownload.ocx ActiveX Remote Code Execution
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RIESGO
abrir ↗Metasploit500
HP AutoPass License Server File Upload
Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoP
60RIESGO
abrir ↗Metasploit600
GetSimpleCMS PHP File Upload Vulnerability
GetSimple CMS 3.2.1 Authenticated RCE via Arbitrary PHP File Upload
36RIESGO
abrir ↗Metasploit600
HP Data Protector Backup Client Service Remote Code Execution
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RIESGO
abrir ↗Metasploit500
HP Data Protector Backup Client Service Directory Traversal
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a
50RIESGO
abrir ↗Metasploit500
HP Client Automation Command Injection
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir ↗Metasploit500
SerComm Device Remote Code Execution
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RIESGO
abrir ↗Metasploit300
SerComm Network Device Backdoor Detection
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RIESGO
abrir ↗Metasploit300
IBM Lotus Sametime Version Enumeration
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspeci
23RIESGO
abrir ↗Metasploit300
IBM Lotus Notes Sametime Room Name Bruteforce
The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to determine whic
18RIESGO
abrir ↗Metasploit300
IBM Lotus Notes Sametime User Enumeration
Unspecified vulnerability in the Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remot
23RIESGO
abrir ↗Metasploit300
RealNetworks RealPlayer Version Attribute Buffer Overflow
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before
50RIESGO
abrir ↗Metasploit300
Adobe Flash Player Type Confusion Remote Code Execution
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2
60RIESGO
abrir ↗Metasploit300
IcoFX Stack Buffer Overflow
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RIESGO
abrir ↗Metasploit500
MS13-097 Registry Symlink IE Sandbox Escape
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and conseque
43RIESGO
abrir ↗Metasploit600
ElasticSearch Dynamic Script Arbitrary Java Execution
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RIESGO
abrir ↗Metasploit600
Zimbra Collaboration Server LFI
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RIESGO
abrir ↗Metasploit300
IBM Forms Viewer Unicode Buffer Overflow
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to exe
50RIESGO
abrir ↗Metasploit300
Ruby on Rails Action View MIME Memory Exhaustion
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allo
23RIESGO
abrir ↗Metasploit200
Windows NTUserMessageCall Win32k Kernel Pool Overflow (Schlamperei)
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.