Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.776GitHub PoC 15.367VulnCheck XDB 9019Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.557 exploits
Exploit-DB
Cerb 7.0.3 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the a
23RIESGO
abrir ↗Exploit-DB
SiS Windows VGA Display Manager 6.14.10.3930 - Write-What-Where (PoC)
Silicon Integrated Systems WindowsXP Display Manager (aka VGA Driver Manager and VGA Display Manager) 6.14.10.3930 allow
23RIESGO
abrir ↗Metasploit600
Nibbleblog File Upload Vulnerability
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir ↗Exploit-DB
XGI Windows VGA Display Manager 6.14.10.1090 - Arbitrary Write (PoC)
Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.10
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bedita 3.5.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in BEdita before 3.6.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB
Cyberoam Firewall CR500iNG-XP 10.6.2 MR-1 - Blind SQL Injection
SQL injection vulnerability in the Sophos Cyberoam CR500iNG-XP firewall appliance with CyberoamOS 10.6.2 MR-1 and earlie
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Boxoft WAV to MP3 Converter - 'convert' Local Buffer Overflow
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RIESGO
abrir ↗Metasploit300
Boxoft WAV to MP3 Converter v1.1 Buffer Overflow
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RIESGO
abrir ↗Exploit-DB
Ganglia Web Frontend < 3.5.1 - PHP Code Execution
Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Entitlements - 'Rootpipe' Local Privilege Escalation (Metasploit)
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allow
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PCMan FTP Server 2.0.7 - 'RENAME' Remote Buffer Overflow
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗Metasploit600
phpFileManager 0.9.8 Remote Code Execution
phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
23RIESGO
abrir ↗Metasploit600
WordPress Responsive Thumbnail Slider Arbitrary File Upload
Responsive Thumbnail Slider < 1.0.1 - Authenticated (Subscriber+) Arbitrary File Upload
36RIESGO
abrir ↗Exploit-DB
Wolf CMS - Arbitrary File Upload / Execution
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir ↗Exploit-DB
Wolf CMS - Arbitrary File Upload / Execution
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle GlassFish Server 4.1 - Directory Traversal
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QEMU - Programmable Interrupt Timer Controller Heap Overflow
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read
23RIESGO
abrir ↗Exploit-DB
Invision Power Board (IP.Board) 4.x - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB,
23RIESGO
abrir ↗GitHub PoC★ 2
An implementation of the CVE-2015-2153 exploit.
The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers t
28RIESGO
abrir ↗Exploit-DB
Linux Kernel < 3.5.0-23 (Ubuntu 12.04.2 x64) - 'SOCK_DIAG' SMEP Bypass Local Privilege Escalation
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows l
23RIESGO
abrir ↗Exploit-DB
Magento eCommerce - Remote Code Execution
SQL injection vulnerability in the getCsvFile function in the Mage_Adminhtml_Block_Widget_Grid class in Magento Communit
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - OneTableDocumentStream Invalid Object
Microsoft Word 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruptio
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 3.6.0 < 4.2.3 - 'ForumRunner' SQL Injection
SQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 bef
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - Malformed Document Stack Buffer Overflow
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word Automation Services in SharePoint Server 2010, Web Applica
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'pdf.js' Privileged JavaScript Injection (Metasploit)
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource
50RIESGO
abrir ↗Exploit-DB
Pligg CMS 2.0.2 - Cross-Site Request Forgery (Add Admin)
Cross-site request forgery (CSRF) vulnerability in Pligg CMS 2.0.2 allows remote attackers to hijack the authentication
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - 'pdf.js' Privileged JavaScript Injection (Metasploit)
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RIESGO
abrir ↗Metasploit300
Konica Minolta FTP Utility 1.00 Post Auth CWD Command SEH Overflow
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RIESGO
abrir ↗Metasploit600
MVPower DVR Shell Unauthenticated Command Execution
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - 'OGL.dll' DpOutputSpanStretch::OutputSpan Out of Bounds Write (MS15-080)
Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lyn
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.