Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
3477 exploits
Metasploit500
Rocket Servergraph Admin Center fileRequestor Remote Code Execution
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows
60RIESGO
abrir ↗Metasploit600
HP LoadRunner EmulationAdmin Web Service Directory Traversal
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb
50RIESGO
abrir ↗Metasploit300
VideoCharge Studio Buffer Overflow (SEH)
VideoCharge Studio 2.12.3.685 SEH Buffer Overflow via .VSC File
36RIESGO
abrir ↗Metasploit600
ProcessMaker Open Source Authenticated PHP Code Execution
ProcessMaker Open Source < 2.5.2 neoclassic Skin PHP Code Execution
36RIESGO
abrir ↗Metasploit600
VICIdial Manager Send OS Command Injection
Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-40
50RIESGO
abrir ↗Metasploit600
VICIdial Manager Send OS Command Injection
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execut
50RIESGO
abrir ↗Metasploit300
Node.js HTTP Pipelining Denial of Service
The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of se
30RIESGO
abrir ↗Metasploit600
WebTester 5.x Command Execution
WebTester 5.x install2.php Unauthenticated Command Execution
63RIESGO
abrir ↗Metasploit300
Beetel Connection Manager NetConfig.ini Buffer Overflow
Beetel Connection Manager NetConfig.ini Stack-Based Buffer Overflow
36RIESGO
abrir ↗Metasploit300
Android Settings Remove Device Locks (4.0-4.3)
Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted ap
18RIESGO
abrir ↗Metasploit300
ALLPlayer M3U Buffer Overflow
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir ↗Metasploit300
vBulletin Administrator Account Creation
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the
50RIESGO
abrir ↗Metasploit200
Windows TrackPopupMenuEx Win32k NULL Page
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to ga
43RIESGO
abrir ↗Metasploit300
HP Intelligent Management SOM Account Creation
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Mod
23RIESGO
abrir ↗Metasploit300
MS13-080 Microsoft Internet Explorer CDisplayPointer Use-After-Free
Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allo
100RIESGO
abrir ↗Metasploit600
HP Intelligent Management Center BIMS UploadServlet Directory Traversal
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Soft
50RIESGO
abrir ↗Metasploit600
ClipBucket Remote Code Execution
ClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCE
63RIESGO
abrir ↗Metasploit600
ibstat $PATH Privilege Escalation
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, a
38RIESGO
abrir ↗Metasploit600
Zabbix 2.0.8 SQL Injection and Remote Code Execution
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
60RIESGO
abrir ↗Metasploit600
ZeroShell Remote Code Execution
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell meta
60RIESGO
abrir ↗Metasploit600
Cisco Prime Data Center Network Manager Arbitrary File Upload
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RIESGO
abrir ↗Metasploit0
Astium Remote Code Execution
Astium VOIP PBX <= 2.1 SQL Injection File Upload RCE
63RIESGO
abrir ↗Metasploit600
F5 iControl Remote Root Command Execution
The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5
50RIESGO
abrir ↗Metasploit300
MS13-080 Microsoft Internet Explorer SetMouseCapture Use-After-Free
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 throug
100RIESGO
abrir ↗Metasploit600
OpenEMR 4.1.1 Patch 14 SQLi Privilege Escalation Remote Code Execution
OpenEMR ≤ 4.1.1 SQL Injection Privilege Escalation and RCE
36RIESGO
abrir ↗Metasploit0
GLPI install.php Remote Command Execution
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installati
38RIESGO
abrir ↗Metasploit300
MS13-069 Microsoft Internet Explorer CCaret Use-After-Free
Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (
50RIESGO
abrir ↗Metasploit600
MS13-071 Microsoft Windows Theme File Handling Arbitrary Code Execution
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, and Windows Server 2008 SP2 allow remote a
68RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.