Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.842 exploits
Exploit-DB
Linux Kernel 3.15.6 - PPP-over-L2TP Socket Level Handling Crash (PoC)
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5 - 'restore.php' (Authenticated) Command Injection (Metasploit)
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RIESGO
abrir ↗Exploit-DB
SolarWinds Orion Service - SQL Injection
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir ↗Exploit-DB
Linux Kernel 3.16.3 - Associative Array Garbage Collection Crash (PoC)
The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16
23RIESGO
abrir ↗Exploit-DB
PHPMoAdmin - Unauthorized Remote Code Execution
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RIESGO
abrir ↗Exploit-DB
WordPress Theme Photocrati 4.x - SQL Injection / Cross-Site Scripting
SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to exec
23RIESGO
abrir ↗Metasploit300
WordPress CP Multi-View Calendar Unauthenticated SQL Injection Scanner
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RIESGO
abrir ↗Metasploit600
PHPMoAdmin 1.1.2 Remote Code Execution
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin vBSEO 4.x - 'visitormessage.php' Remote Code Injection
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v
28RIESGO
abrir ↗Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RIESGO
abrir ↗Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir ↗Metasploit300
Seagate Business NAS Unauthenticated Remote Command Execution
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS 2014.00319 - Remote Code Execution
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir ↗Exploit-DB
Persistent Systems Client Automation - Command Injection Remote Code Execution (Metasploit)
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir ↗Metasploit300
D-Link/TRENDnet NCC Service Command Injection
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RIESGO
abrir ↗Exploit-DB
SQLite3 3.8.6 - Controlled Memory Corruption (PoC)
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link/TRENDnet - NCC Service Command Injection (Metasploit)
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RIESGO
abrir ↗Metasploit300
WordPress WP EasyCart Plugin Privilege Escalation
The ec_ajax_update_option and ec_ajax_clear_all_taxrates functions in inc/admin/admin_ajax_functions.php in the WP EasyC
23RIESGO
abrir ↗Metasploit300
WordPress Contus Video Gallery Unauthenticated SQL Injection Scanner
SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b
50RIESGO
abrir ↗Metasploit300
Solarwinds Orion AccountManagement.asmx GetAccounts Admin Creation
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Client - Automation Command Injection (Metasploit)
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls th
23RIESGO
abrir ↗Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to
23RIESGO
abrir ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in ZeusCart 4 allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in the administrative backend in ZeusCart 4 allow remote administrators to execut
23RIESGO
abrir ↗Exploit-DB
PHP DateTime - Use-After-Free
Multiple use-after-free vulnerabilities in ext/date/php_date.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x befo
35RIESGO
abrir ↗Metasploit500
D-Link DCS-931L File Upload
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin Easy Social Icons 1.2.2 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.