Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.805exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.428VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.805 exploits
Metasploit300
WordPress CP Multi-View Calendar Unauthenticated SQL Injection Scanner
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RIESGO
abrir ↗Metasploit600
PHPMoAdmin 1.1.2 Remote Code Execution
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RIESGO
abrir ↗Exploit-DB
PHPMoAdmin - Unauthorized Remote Code Execution
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin vBSEO 4.x - 'visitormessage.php' Remote Code Injection
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS 2014.00319 - Remote Code Execution
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir ↗Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RIESGO
abrir ↗Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir ↗Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RIESGO
abrir ↗Exploit-DB
Persistent Systems Client Automation - Command Injection Remote Code Execution (Metasploit)
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir ↗Exploit-DB
SQLite3 3.8.6 - Controlled Memory Corruption (PoC)
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link/TRENDnet - NCC Service Command Injection (Metasploit)
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RIESGO
abrir ↗Metasploit300
D-Link/TRENDnet NCC Service Command Injection
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RIESGO
abrir ↗Metasploit300
WordPress WP EasyCart Plugin Privilege Escalation
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyC
23RIESGO
abrir ↗Metasploit300
WordPress Contus Video Gallery Unauthenticated SQL Injection Scanner
SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b
50RIESGO
abrir ↗Metasploit300
Solarwinds Orion AccountManagement.asmx GetAccounts Admin Creation
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Client - Automation Command Injection (Metasploit)
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execut
23RIESGO
abrir ↗Exploit-DB
Beehive Forum 1.4.4 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to i
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Easy Social Icons 1.2.2 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote
23RIESGO
abrir ↗Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authe
23RIESGO
abrir ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗Metasploit500
D-Link DCS-931L File Upload
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use
50RIESGO
abrir ↗Exploit-DB
Zabbix 2.0.5 - Cleartext ldap_bind_Password Password Disclosure (Metasploit)
Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console acces
23RIESGO
abrir ↗Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to
23RIESGO
abrir ↗Exploit-DB
PHP DateTime - Use-After-Free
Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x befo
35RIESGO
abrir ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls th
23RIESGO
abrir ↗Exploit-DB
Clipbucket 2.7 RC3 0.9 - Blind SQL Injection
SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execut
23RIESGO
abrir ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attac
23RIESGO
abrir ↗Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.