Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.934GitHub PoC 13.235VulnCheck XDB 8150Nuclei 4193Metasploit 3462✓ solo verificadosrecientespopularesriesgo
3462 exploits
Metasploit600
SonicWALL GMS 6 Arbitrary File Upload
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5
60RIESGO
abrir ↗Metasploit300
Irfanview JPEG2000 jp2 Stack Buffer Overflow
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute a
50RIESGO
abrir ↗Metasploit200
HP Diagnostics Server magentservice.exe Overflow
Stack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attac
50RIESGO
abrir ↗Metasploit300
NTR ActiveX Control StopModule() Remote Code Execution
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a
50RIESGO
abrir ↗Metasploit300
NTR ActiveX Control Check() Method Buffer Overflow
Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitr
50RIESGO
abrir ↗Metasploit500
HP Easy Printer Care XMLCacheMgr Class ActiveX Control Remote Code Execution
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to
50RIESGO
abrir ↗Metasploit600
MS12-005 Microsoft Office ClickOnce Unsafe Object Package Handling Vulnerability
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Se
60RIESGO
abrir ↗Metasploit300
MS12-004 midiOutPlayNextPolyEvent Heap Overflow
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RIESGO
abrir ↗Metasploit600
Apache Struts 2 Developer Mode OGNL Execution
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RIESGO
abrir ↗Metasploit600
Apache Struts Remote Command Execution
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during
100RIESGO
abrir ↗Metasploit600
OP5 welcome Remote Command Execution
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers
60RIESGO
abrir ↗Metasploit600
OP5 license.php Remote Command Execution
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execu
60RIESGO
abrir ↗Metasploit300
Hashtable Collisions
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions pre
60RIESGO
abrir ↗Metasploit300
Hashtable Collisions
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 a
50RIESGO
abrir ↗Metasploit300
Hashtable Collisions
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger ha
60RIESGO
abrir ↗Metasploit300
Hashtable Collisions
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without r
60RIESGO
abrir ↗Metasploit400
CoCSoft StreamDown 6.8.0 Buffer Overflow
Stack-based buffer overflow in CoCSoft Stream Down 6.8.0 allows remote web servers to execute arbitrary code via a long
50RIESGO
abrir ↗Metasploit500
FreeBSD Telnet Service Encryption Key ID Buffer Overflow
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RIESGO
abrir ↗Metasploit500
Linux BSD-derived Telnet Service Encryption Key ID Buffer Overflow
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RIESGO
abrir ↗Metasploit600
HP Managed Printing Administration jobAcct Remote Command Execution
Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration
50RIESGO
abrir ↗Metasploit300
7-Technologies IGSS 9 IGSSdataServer.exe DoS
Buffer overflow in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11200 allows remote attackers to
23RIESGO
abrir ↗Metasploit300
Enterasys NetSight nssyslogd.exe Buffer Overflow
Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1
60RIESGO
abrir ↗Metasploit300
MS11-093 Microsoft Windows OLE Object File Handling Remote Code Execution
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote a
60RIESGO
abrir ↗Metasploit600
Splunk Search Remote Code Execution
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python
43RIESGO
abrir ↗Metasploit300
IpSwitch WhatsUp Gold TFTP Directory Traversal
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read a
50RIESGO
abrir ↗Metasploit600
Traq admincp/common.php Remote Code Execution
Traq 2.0–2.3 admincp/common.php RCE
63RIESGO
abrir ↗Metasploit600
Solarwinds Storage Manager 5.1.0 SQL Injection
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof
50RIESGO
abrir ↗Metasploit400
TrendMicro Control Manger CmdProcessor.exe Stack Buffer Overflow
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcess
50RIESGO
abrir ↗Metasploit200
Adobe Reader U3D Memory Corruption Vulnerability
Unspecified vulnerability in the U3D component in Adobe Reader and Acrobat 10.1.1 and earlier on Windows and Mac OS X, a
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.