Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
Metasploit600
MS16-016 mrxdav.sys WebDav Local Privilege Escalation
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (1)
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RIESGO
abrir ↗VulnCheck XDB
initial-access
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir ↗GitHub PoC
CVE-2015-8562 Exploit in bash
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir ↗GitHub PoC★ 41
Trigger and exploit code for CVE-2014-4113
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir ↗VulnCheck XDB
local
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir ↗Metasploit600
Advantech WebAccess Dashboard Viewer uploadImageCommon Arbitrary File Upload
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess
60RIESGO
abrir ↗Metasploit500
D-Link DSL-2750B OS Command Injection
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as
100RIESGO
abrir ↗Metasploit600
NETGEAR ProSafe Network Management System 300 Arbitrary File Upload
NETGEAR ProSAFE Network Management System UpLoadServlet Unrestricted File Upload Remote Code Execution Vulnerability
41RIESGO
abrir ↗Metasploit600
NETGEAR ProSafe Network Management System 300 Arbitrary File Upload
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RIESGO
abrir ↗Metasploit300
NETGEAR ProSafe Network Management System 300 Authenticated File Download
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote
60RIESGO
abrir ↗Metasploit600
NETGEAR ProSafe Network Management System 300 Arbitrary File Upload
NETGEAR ProSAFE Network Management System MyHandlerInterceptor Authentication Bypass Vulnerability
65RIESGO
abrir ↗Exploit-DB
Netgear NMS300 ProSafe Network Management System - Multiple Vulnerabilities
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GE Industrial Solutions UPS SNMP Adapter < 4.8 - Multiple Vulnerabilities
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
28RIESGO
abrir ↗Exploit-DB
D-Link DVGN5402SP - Multiple Vulnerabilities
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root accou
28RIESGO
abrir ↗Exploit-DB
D-Link DVGN5402SP - Multiple Vulnerabilities
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and
28RIESGO
abrir ↗Exploit-DB
D-Link DVGN5402SP - Multiple Vulnerabilities
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GE Industrial Solutions UPS SNMP Adapter < 4.8 - Multiple Vulnerabilities
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
23RIESGO
abrir ↗Exploit-DB
Netgear NMS300 ProSafe Network Management System - Multiple Vulnerabilities
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote
60RIESGO
abrir ↗VulnCheck XDB
infoleak
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir ↗GitHub PoC★ 31
[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir ↗GitHub PoC★ 30
[discontinued] Mass exploiter of CVE-2015-1579 for WordPress CMS
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir ↗Exploit-DB
Viprinet Multichannel VPN Router 300 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the old and new interfaces in Viprinet Multichannel VPN Router 30
23RIESGO
abrir ↗Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the a
23RIESGO
abrir ↗Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allow
23RIESGO
abrir ↗Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserServ
23RIESGO
abrir ↗Metasploit600
lastore-daemon D-Bus Privilege Escalation
Deepin lastore-daemon Privilege Escalation via Unsigned .deb Installation
36RIESGO
abrir ↗Exploit-DB
eClinicalWorks (CCMR) - Multiple Vulnerabilities
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RIESGO
abrir ↗Exploit-DB
Microsoft Internet Explorer 11 - javascript Code Execution
JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial o
83RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iOS Kernel - IOReportHub Use-After-Free
The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain pri
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.