Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit600
WordPress OptimizePress Theme File Upload Vulnerability
Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-
23RIESGO
abrir ↗Metasploit200
MS14-002 Microsoft Windows ndproxy.sys Local Privilege Escalation
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RIESGO
abrir ↗Metasploit300
Total Video Player 1.3.1 (Settings.ini) - SEH Buffer Overflow
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RIESGO
abrir ↗Metasploit300
Ruby on Rails JSON Processor Floating Point Heap Overflow DoS
Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and tru
30RIESGO
abrir ↗Metasploit600
Idera Up.Time Monitoring Station 7.0 post2file.php Arbitrary File Upload
Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
63RIESGO
abrir ↗Metasploit300
Red Hat CloudForms Management Engine 5.1 miq_policy/explorer SQL Injection
SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and Mana
23RIESGO
abrir ↗Metasploit300
Huawei Datacard Information Disclosure Vulnerability
The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remot
18RIESGO
abrir ↗Metasploit600
ManageEngine Desktop Central AgentLogUpload Arbitrary File Upload
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RIESGO
abrir ↗Metasploit600
Kaseya uploadImage Arbitrary File Upload
Kaseya < 6.3.0.2 uploadImage.asp Arbitrary File Upload RCE
63RIESGO
abrir ↗Metasploit300
MS13-090 CardSpaceClaimCollection ActiveX Integer Underflow
The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server
100RIESGO
abrir ↗Metasploit300
IBM Lotus Sametime WebPlayer DoS
IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension c
18RIESGO
abrir ↗Metasploit400
Supermicro Onboard IPMI close_window.cgi Buffer Overflow
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Managemen
60RIESGO
abrir ↗Metasploit300
Supermicro Onboard IPMI CGI Vulnerability Scanner
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Managemen
60RIESGO
abrir ↗Metasploit300
Supermicro Onboard IPMI url_redirect.cgi Authenticated Directory Traversal
Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attacker
18RIESGO
abrir ↗Metasploit300
Supermicro Onboard IPMI Static SSL Certificate Scanner
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_3
18RIESGO
abrir ↗Metasploit200
MS13-096 Microsoft Tagged Image File Format (TIFF) Integer Overflow
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati
100RIESGO
abrir ↗Metasploit600
Gitlab-shell Code Execution
The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x
50RIESGO
abrir ↗Metasploit300
Watermark Master Buffer Overflow (SEH)
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir ↗Metasploit600
Synology DiskStation Manager SLICEUPLOAD Remote Command Execution
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before
60RIESGO
abrir ↗Metasploit600
Apache Roller OGNL Injection
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute
60RIESGO
abrir ↗Metasploit500
Rocket Servergraph Admin Center fileRequestor Remote Code Execution
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows
60RIESGO
abrir ↗Metasploit600
Moodle Authenticated Spelling Binary RCE
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell
50RIESGO
abrir ↗Metasploit600
Zabbix Authenticated Remote Command Execution
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
50RIESGO
abrir ↗Metasploit600
Moodle Authenticated Spelling Binary RCE
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, an
43RIESGO
abrir ↗Metasploit300
Openbravo ERP XXE Arbitrary File Read
The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML
43RIESGO
abrir ↗Metasploit600
OpenMediaVault rpc.php Authenticated Cron Remote Code Execution
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users
68RIESGO
abrir ↗Metasploit600
HP LoadRunner EmulationAdmin Web Service Directory Traversal
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb
50RIESGO
abrir ↗Metasploit500
NAS4Free Arbitrary Remote Code Execution
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.p
43RIESGO
abrir ↗Metasploit500
HP SiteScope issueSiebelCmd Remote Code Execution
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authenti
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.