Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.392VulnCheck XDB 9029Nuclei 4416Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.646 exploits
Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code
28RIESGO
abrir ↗Metasploit500
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RIESGO
abrir ↗Metasploit500
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows an
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS < 2.0.3 - Multiple Vulnerabilities
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tango DropBox 3.1.5 + PRO - Activex HeapSpray
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSell
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lively Cart - SQL Injection
SQL injection vulnerability in LivelyCart 1.2.0 allows remote attackers to execute arbitrary SQL commands via the search
23RIESGO
abrir ↗Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authentica
23RIESGO
abrir ↗Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to writ
28RIESGO
abrir ↗GitHub PoC★ 1
This is an Android Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB
BlackCat CMS 1.1.1 - Arbitrary File Download
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbit
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ruby on Rails 4.0.x/4.1.x/4.2.x (Web Console v2) - Whitelist Bypass Code Execution (Metasploit)
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir ↗Exploit-DB
Ektron CMS 9.10 SP1 (Build 9.1.0.184.1.114) - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Test/WorkArea/DmsMenu/menuActions/MenuActions.aspx in Ektron Content
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir ↗Exploit-DB
TYPO3 Extension Akronymmanager 0.5.0 - SQL Injection
SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation (Access /etc/shadow)
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir ↗Metasploit400
Overlayfs Privilege Escalation
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir ↗Metasploit400
Overlayfs Privilege Escalation
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir ↗Metasploit600
Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Milw0rm Clone Script 1.0 - '/admin/login.php' Authentication Bypass
Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Aviary Image Editor Addon For Gravity Forms 3.0 Beta - Arbitrary File Upload
Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZCMS 1.1 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.
23RIESGO
abrir ↗Exploit-DB
ClickHeat 1.14 - Cross-Site Request Forgery (Change Admin Password)
Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the auth
23RIESGO
abrir ↗Metasploit300
D-Link Cookie Command Execution
D-Link DSP-W110A1 Cookie Command Injection
63RIESGO
abrir ↗Exploit-DB
Opsview 4.6.2 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin SE HTML5 Album Audio Player 1.1.0 - Directory Traversal
Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player)
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZCMS 1.1 - Multiple Vulnerabilities
SQL injection vulnerability in ZCMS 1.1.
23RIESGO
abrir ↗Exploit-DB
OSSEC 2.7 < 2.8.1 - 'diff' Local Privilege Escalation
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
23RIESGO
abrir ↗Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir ↗Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.