Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.842 exploits
Exploit-DB
WordPress Plugin Pixarbay Images 2.3 - Multiple Vulnerabilities
Directory traversal vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress allows rem
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Pixarbay Images 2.3 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress all
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Cforms 14.7 - Remote Code Execution
Unrestricted file upload vulnerability in lib_nonajax.php in the CformsII plugin 14.7 and earlier for WordPress allows r
28RIESGO
abrir ↗Exploit-DB
Samsung SmartViewer BackupToAvi 3.0 - Remote Code Execution
Stack-based buffer overflow in the BackupToAvi method in the CNC_Ctrl ActiveX control in Samsung SmartViewer allows remo
23RIESGO
abrir ↗Metasploit600
WordPress Pixabay Images PHP Code Upload
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remot
50RIESGO
abrir ↗Exploit-DB
Lorex LH300 Series - ActiveX Buffer Overflow (PoC)
Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows < 8.1 (x86/x64) - User Profile Service Privilege Escalation (MS15-003)
The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2
23RIESGO
abrir ↗Exploit-DB
Sim Editor 6.6 - Local Stack Buffer Overflow
Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary co
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin Pie Register 2.0.13 - Privilege Escalation
The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-regist
23RIESGO
abrir ↗Exploit-DB
ManageEngine Desktop Central - Create Administrator
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at
60RIESGO
abrir ↗Exploit-DB
Ansible Tower 2.0.2 - Multiple Vulnerabilities
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive inform
23RIESGO
abrir ↗Exploit-DB
Ansible Tower 2.0.2 - Multiple Vulnerabilities
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a s
23RIESGO
abrir ↗GitHub PoC★ 2
tjjh89017/cve-2014-6332
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Exploit-DB
Ansible Tower 2.0.2 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attacker
23RIESGO
abrir ↗Exploit-DB
Gecko CMS 2.3 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB
Gecko CMS 2.3 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote administrators to execute arbitrary SQL com
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle MySQL (Windows) - FILE Privilege Abuse (Metasploit)
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗Exploit-DB
Gecko CMS 2.3 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote attackers to hijack the authentic
23RIESGO
abrir ↗Metasploit400
MS15-004 Microsoft Remote Desktop Services Web Proxy IE Sandbox Escape
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RIESGO
abrir ↗Exploit-DB
Dell iDRAC IPMI 1.5 - Insufficient Session ID Randomness
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lexmark MarkVision Enterprise - Arbitrary File Upload (Metasploit)
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo
60RIESGO
abrir ↗GitHub PoC★ 18
cve2014-3153 exploit for ubuntu x86
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗VulnCheck XDB
local
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗Exploit-DB
D-Link DSL-2730B Modem - Cross-Site Scripting Injection Stored DnsProxy.cmd
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RIESGO
abrir ↗Exploit-DB
D-Link DSL-2730B Modem - Cross-Site Scripting Injection Stored Wlsecrefresh.wl & Wlsecurity.wl
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RIESGO
abrir ↗Exploit-DB
D-Link DSL-2730B Modem - 'Lancfg2get.cgi Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2730B router (rev C1) with firmware GE_1.01 allow remo
23RIESGO
abrir ↗Exploit-DB
Apple Mac OSX 10.9.x - sysmond XPC Privilege Escalation
The xpc_data_get_bytes function in libxpc in Apple OS X before 10.10.2 does not verify that a dictionary's Attributes ke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pandora FMS 3.1 - Authentication Bypass / Arbitrary File Upload (Metasploit)
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RIESGO
abrir ↗Metasploit600
WordPress WP EasyCart Unrestricted File Upload
Unrestricted file upload vulnerability in inc/amfphp/administration/banneruploaderscript.php in the WP EasyCart (aka Wor
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.