Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.753exploits catalogados
37.445CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.871GitHub PoC 15.407VulnCheck XDB 9065Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.753 exploits
VulnCheck XDB
local
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir ↗GitHub PoC★ 4
CVE-2015-0235 EXIM ESTMP GHOST Glibc Gethostbyname() DoS Exploit/PoC
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir ↗Exploit-DB
WebGate Control Center 4.8.7 - GetThumbnail Stack Overflow
Multiple buffer overflows in WebGate Control Center allow remote attackers to execute arbitrary code via unspecified vec
28RIESGO
abrir ↗Exploit-DB
Berta CMS - Arbitrary File Upload
Unrestricted file upload vulnerability in Berta CMS allows remote attackers to execute arbitrary code by uploading a cra
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Acunetix 9.5 - OLE Automation Array Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Exploit-DB
WebGate eDVR Manager 2.6.4 - SiteName Stack Overflow
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RIESGO
abrir ↗Exploit-DB
WebGate WinRDS 2.0.8 - StopSiteAllChannel Stack Overflow
Stack-based buffer overflow in the WESPPlayback.WESPPlaybackCtrl.1 control in WebGate WinRDS allows remote attackers to
28RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Exploit-DB
RM Downloader 2.7.5.400 - Local Buffer Overflow
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗GitHub PoC★ 3
Spider Exploit with CVE-2013-2842
Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service o
28RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
WebGate eDVR Manager - Remote Stack Buffer Overflow
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Exploit-DB
pfSense 2.2 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RIESGO
abrir ↗Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RIESGO
abrir ↗Exploit-DB
Adobe Flash Player - Arbitrary Code Execution
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.