Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.776GitHub PoC 15.367VulnCheck XDB 9019Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.557 exploits
Exploit-DB✓ VexDay Proof
AirLink101 SkyIPCam1620W - OS Command Injection
snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Easy2Map 1.24 - SQL Injection
Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - ByteArray Use-After-Free (Metasploit)
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir ↗Exploit-DB
Centreon 2.5.4 - Multiple Vulnerabilities
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows an
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin Easy2Map 1.24 - SQL Injection
Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP E-Commerce Shop Styling 2.5 - Arbitrary File Download
Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attack
28RIESGO
abrir ↗Exploit-DB
phpLiteAdmin 1.1 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication
23RIESGO
abrir ↗Exploit-DB
phpLiteAdmin 1.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB
INFOMARK IMW-C920W MiniUPnPd 1.0 - Denial of Service
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attacke
60RIESGO
abrir ↗Exploit-DB
INFOMARK IMW-C920W MiniUPnPd 1.0 - Denial of Service
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP
50RIESGO
abrir ↗Metasploit500
Adobe Flash Player ByteArray Use After Free
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir ↗Metasploit500
Adobe Flash opaqueBackground Use After Free
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RIESGO
abrir ↗Exploit-DB
PHPXMLRPC < 1.1 - Remote Code Execution
Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PH
60RIESGO
abrir ↗Metasploit500
Apple OS X Entitlements Rootpipe Privilege Escalation
Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allow
38RIESGO
abrir ↗Exploit-DB
C2Box 4.0.0(r19171) - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in SecuritySetting/UserSecurity/UserManagement.aspx in B.A.S C2Box befor
23RIESGO
abrir ↗Exploit-DB
Watchguard XCS 10.0 - Multiple Vulnerabilities
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB
Fiyo CMS 2.0_1.9.1 - SQL Injection
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Exploit-DB
Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potenti
23RIESGO
abrir ↗Exploit-DB
Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain p
23RIESGO
abrir ↗Exploit-DB
Watchguard XCS 10.0 - Multiple Vulnerabilities
The STARTTLS implementation in WatchGuard XCS 9.0 and 9.1 does not properly restrict I/O buffering, which allows man-in-
23RIESGO
abrir ↗Exploit-DB
Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - Drawing Fill Shader Memory Corruption (Metasploit)
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466
60RIESGO
abrir ↗Exploit-DB
Novius 5.0.1 - Multiple Vulnerabilities
Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites
43RIESGO
abrir ↗Exploit-DB
Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation
23RIESGO
abrir ↗Exploit-DB
Polycom RealPresence Resource Manager < 8.4 - Multiple Vulnerabilities
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors re
23RIESGO
abrir ↗Exploit-DB
Novius 5.0.1 - Multiple Vulnerabilities
Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary lo
23RIESGO
abrir ↗Exploit-DB
Endian Firewall < 3.0.0 - OS Command Injection
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir ↗Exploit-DB
DeDeCMS < 5.7-sp1 - Remote File Inclusion
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
35RIESGO
abrir ↗Metasploit600
Watchguard XCS Remote Command Execution
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.