Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.790exploits catalogados
37.482CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.414VulnCheck XDB 9065Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.790 exploits
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RIESGO
abrir ↗Exploit-DB
Adobe Flash Player - Arbitrary Code Execution
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - Proxy Prototype Privileged JavaScript Injection (Metasploit)
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RIESGO
abrir ↗GitHub PoC★ 21
SecurityObscurity/cve-2015-0313
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RIESGO
abrir ↗Exploit-DB
Telescope 0.9.2 - Markdown Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary
23RIESGO
abrir ↗GitHub PoC
Using google to scan sites for "ShellShock" (CVE-2014-6271)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit300
Web-Dorado ECommerce WD for Joomla! search_category_id SQL Injection Scanner
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allo
50RIESGO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB
Citrix Command Center - Credential Disclosure
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via
28RIESGO
abrir ↗Exploit-DB
EMC M&R (Watch4net) - Directory Traversal
Directory traversal vulnerability in EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 allows remote authen
23RIESGO
abrir ↗Exploit-DB
EMC M&R (Watch4net) - Credential Disclosure
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-cen
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TWiki Debugenableplugins - Remote Code Execution (Metasploit)
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Publish-It - '.PUI' Local Buffer Overflow (SEH) (Metasploit)
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir ↗Exploit-DB
Citrix Nitro SDK - Command Injection
Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote
23RIESGO
abrir ↗Exploit-DB
Joomla! Component ECommerce-WD 1.2.5 - SQL Injection
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet Single Sign On - Stack Overflow
Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir ↗Exploit-DB
Websense Appliance Manager - Command Injection
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - PCRE Regex (Metasploit)
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RIESGO
abrir ↗Exploit-DB
Moodle 2.5.9/2.6.8/2.7.5/2.8.3 - Block Title Handler Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in lib/javascript-static.js in Moodle through 2.5.9, 2.6.x before 2.
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin WPML 3.1.9 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin SEO by Yoast 1.7.3.3 - Blind SQL Injection
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.