Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.646exploits catalogados
37.382CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.825GitHub PoC 15.392VulnCheck XDB 9029Nuclei 4416Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.646 exploits
Exploit-DB
WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion
Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attack
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SysAid Help Desk Administrator Portal < 14.4 - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RIESGO
abrir ↗Metasploit300
SysAid Help Desk Arbitrary File Download
SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the account
50RIESGO
abrir ↗Metasploit300
SysAid Help Desk Administrator Account Creation
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers t
50RIESGO
abrir ↗Metasploit300
SysAid Help Desk Arbitrary File Download
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir ↗Metasploit300
SysAid Help Desk Database Credentials Disclosure
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir ↗Metasploit300
SysAid Help Desk Database Credentials Disclosure
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir ↗Metasploit600
SysAid Help Desk Administrator Portal Arbitrary File Upload
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RIESGO
abrir ↗Metasploit600
SysAid Help Desk 'rdslogs' Arbitrary File Upload
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link Devices - HNAP SOAPAction-Header Command Execution (Metasploit)
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute ar
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Realtek SDK - Miniigd UPnP SOAP Command Execution (Metasploit)
The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClien
100RIESGO
abrir ↗Exploit-DB
Aruba ClearPass Policy Manager - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Airties - login-cgi Buffer Overflow (Metasploit)
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RIESGO
abrir ↗Exploit-DB
Peercast < 0.1211 - Format String
Format string vulnerability in PeerCast 0.1211 and earlier allows remote attackers to execute arbitrary code via format
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Free Counter 1.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Landing Pages 1.8.4 - Multiple Vulnerabilities
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin NewStatPress 0.9.8 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPres
38RIESGO
abrir ↗Exploit-DB
Apache JackRabbit - WebDAV XML External Entity
XML external entity (XXE) vulnerability in Apache Jackrabbit before 2.0.6, 2.2.x before 2.2.14, 2.4.x before 2.4.6, 2.6.
35RIESGO
abrir ↗Exploit-DB
WordPress Plugin church_admin 0.800 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers t
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin NewStatPress 0.9.8 - Multiple Vulnerabilities
SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remo
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sendio ESP - Information Disclosure
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sendio ESP - Information Disclosure
Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Landing Pages 1.8.4 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin GigPress 2.3.8 - SQL Injection
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
28RIESGO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
28RIESGO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
Double free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 R2, and
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in M
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation (MS15-010)
The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Window
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.