Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.753exploits catalogados
37.445CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.871GitHub PoC 15.407VulnCheck XDB 9065Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.753 exploits
Exploit-DB✓ VexDay Proof
WebGate eDVR Manager 2.6.4 - AudioOnlySiteChannel Stack Buffer Overflow
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Simple Ads Manager 2.5.94 - Arbitrary File Upload
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin before 2.5.96 for WordPres
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Simple Ads Manager - Information Disclosure
WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.
28RIESGO
abrir ↗Exploit-DB
WebGate WinRDS 2.0.8 - PlaySiteAllChannel Stack Buffer Overflow
Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to
28RIESGO
abrir ↗Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Simple Ads Manager - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke
23RIESGO
abrir ↗Exploit-DB
Kemp Load Master 7.1.16 - Multiple Vulnerabilities
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit600
Ceragon FibeAir IP-10 SSH Private Key Exposure
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ceragon FibeAir IP-10 - SSH Private Key Exposure (Metasploit)
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RIESGO
abrir ↗Exploit-DB
Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB
Airties Air5650TT - Remote Stack Overflow
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RIESGO
abrir ↗Exploit-DB
Palo Alto Traps Server 3.1.2.1546 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks
23RIESGO
abrir ↗Exploit-DB
Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities
Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup fil
28RIESGO
abrir ↗Metasploit0
Firefox PDF.js Privileged Javascript Injection
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RIESGO
abrir ↗Metasploit600
Apport / ABRT chroot Privilege Escalation
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RIESGO
abrir ↗Metasploit0
Firefox PDF.js Privileged Javascript Injection
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource
50RIESGO
abrir ↗Metasploit300
Airties login-cgi Buffer Overflow
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 502
60RIESGO
abrir ↗Exploit-DB
Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB
Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities
Directory traversal vulnerability in kcfinder/browse.php in Vtiger CRM before 6.0.0 Security patch 1 allows remote authe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - ByteArray With Workers Use-After-Free (Metasploit)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir ↗Exploit-DB
Fiyo CMS 2.0.1.8 - Multiple Vulnerabilities
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update"
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Slider REvolution 4.1.4 - Arbitrary File Download
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote att
28RIESGO
abrir ↗Exploit-DB
Joomla! Component Contact Form Maker 1.0.1 - SQL Injection
SQL injection vulnerability in Joomla! Component Contact Form Maker 1.0.1 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Slider REvolution 4.1.4 - Arbitrary File Download
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir ↗Exploit-DB
Fedora 21 setroubleshootd 3.2.22 - Local Privilege Escalation
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to ex
28RIESGO
abrir ↗GitHub PoC★ 3
CVE-2013-2094 kernel exploit for i386
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.