Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8195Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
3462 exploits
Metasploit300
OpenSSL DTLS ChangeCipherSpec Remote DoS
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and
60RIESGO
abrir ↗Metasploit300
Cisco IOS HTTP GET /%% Request Denial of Service
The IOS HTTP service in Cisco routers and switches running IOS 11.1 through 12.1 allows remote attackers to cause a deni
50RIESGO
abrir ↗Metasploit400
UoW IMAP Server LSUB Buffer Overflow
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RIESGO
abrir ↗Metasploit600
RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution
The web GUI for the Linux Virtual Server (LVS) software in the Red Hat Linux Piranha package has a backdoor password tha
60RIESGO
abrir ↗Metasploit600
RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution
The passwd.php3 CGI script in the Red Hat Piranha Virtual Server Package allows local users to execute arbitrary command
50RIESGO
abrir ↗Metasploit300
ARP Spoof
The ARP protocol allows any host to spoof ARP replies and poison the ARP cache to conduct IP address spoofing or a denia
23RIESGO
abrir ↗Metasploit600
Matt Wright guestbook.pl Arbitrary Command Execution
guestbook.pl cleanses user-inserted SSI commands by removing text between "<!--" and "-->" separators, which allows remo
60RIESGO
abrir ↗Metasploit0
Microsoft Windows Authenticated User Code Execution
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit600
Powershell Remoting Remote Command Execution
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit600
Windows Management Instrumentation (WMI) Remote Command Execution
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit0
SSH User Code Execution
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit600
PsExec via Current User Token
A Windows NT local user or administrator account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit600
MS99-025 Microsoft IIS MDAC msadcs.dll RDS Arbitrary Remote Command Execution
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x expose
60RIESGO
abrir ↗Metasploit200
War-FTPD 1.65 Username Overflow
Buffer overflow in War FTP allows remote execution of commands.
60RIESGO
abrir ↗Metasploit200
War-FTPD 1.65 Password Overflow
Buffer overflow in War FTP allows remote execution of commands.
60RIESGO
abrir ↗Metasploit300
X11 Keylogger
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
23RIESGO
abrir ↗Metasploit300
Chargen Probe Utility
Echo and chargen, or other combinations of UDP services, can be used in tandem to flood the server, a.k.a. UDP bomb or U
23RIESGO
abrir ↗Metasploit600
Solaris ypupdated Command Execution
The SunView (SunTools) selection_svc facility allows remote users to read files.
50RIESGO
abrir ↗Metasploit300
Haserl Arbitrary File Reader
Lack of verification in haserl, a component of Alpine Linux Configuration Framework, before 0.9.36 allows local users to
18RIESGO
abrir ↗Metasploit300
Linux DoS Xen 4.2.0 2012-5525
The get_page_from_gfn hypercall function in Xen 4.2 allows local PV guest OS administrators to cause a denial of service
18RIESGO
abrir ↗Metasploit300
Check For and Prep the Pyrotechnic Devices (Airbags, Battery Clamps, etc.)
The airbag detonation algorithm allows injury to passenger-car occupants via predictable Security Access (SA) data to th
18RIESGO
abrir ↗Metasploit300
UDP Amplification Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir ↗Metasploit300
SSDP ssdp:all M-SEARCH Amplification Scanner
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP
50RIESGO
abrir ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attacke
60RIESGO
abrir ↗Metasploit300
UPnP SSDP M-SEARCH Information Discovery
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir ↗Metasploit300
Varnish Cache CLI File Read
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy serve
50RIESGO
abrir ↗Metasploit300
Varnish Cache CLI Login Utility
The Command Line Interface (aka Server CLI or administration interface) in the master process in the reverse proxy serve
50RIESGO
abrir ↗Metasploit300
VMware Authentication Daemon Login Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.