Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.010VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
Rowhammer - NaCl Sandbox Escape
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel (x86-64) - Rowhammer Privilege Escalation
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rowhammer - NaCl Sandbox Escape
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates fo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector 8.10 - Remote Command Execution (Metasploit)
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5 - 'restore.php' (Authenticated) Command Injection (Metasploit)
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin vBSEO 4.x - 'visitormessage.php' Remote Code Injection
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS 2014.00319 - Remote Code Execution
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link/TRENDnet - NCC Service Command Injection (Metasploit)
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Client - Automation Command Injection (Metasploit)
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Publish-It 3.6d - Local Buffer Overflow (SEH)
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Java JMX - Server Insecure Configuration Java Code Execution (Metasploit)
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not r
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Fancybox 3.0.2 - Persistent Cross-Site Scripting
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote atta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Webdorado Spider Event Calendar 1.4.9 - SQL Injection
SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQ
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SixApart MovableType < 5.2.12 - Storable Perl Code Execution (Metasploit)
Movable Type Pro, Open Source, and Advanced before 5.2.12 and Pro and Advanced 6.0.x before 6.0.7 does not properly use
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Theme Holding Pattern - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in admin/upload-file.php in the Holding Pattern theme (aka holding_pattern) 0.6 a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP EasyCart - Unrestricted Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Remote Desktop Services - Web Proxy IE Sandbox Escape (MS15-004) (Metasploit)
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to o
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector 8.x - Remote Command Execution
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Encryption Management Server < 3.2.0 MP6 - Remote Command Injection
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrator
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - Multiple Vulnerabilities
Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - Multiple Vulnerabilities
Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 be
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inje
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Android WiFi-Direct - Denial of Service
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ferretCMS 1.0.4-alpha - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.