Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.842 exploits
Metasploit300
Allegro Software RomPager 'Misfortune Cookie' (CVE-2014-9222) Authentication Bypass
AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows re
30RIESGO
abrir ↗GitHub PoC★ 3
CVE-2014-0196: Linux kernel pty layer race condition memory corruption
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir ↗VulnCheck XDB
local
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver a
68RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Malwarebytes Anti-Malware < 2.0.3 / Anti-Exploit < 1.03.1.1220 - Update Code Execution (Metasploit)
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RIESGO
abrir ↗Exploit-DB
CMS Papoo 6.0.0 Rev. 4701 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in CMS Papoo Light 6.0.0 (Rev 4701) allow remote attackers to inject
23RIESGO
abrir ↗Metasploit400
Malwarebytes Anti-Malware and Anti-Exploit Update Remote Code Execution
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RIESGO
abrir ↗Metasploit600
Symantec Web Gateway 5 restore.php Post Authentication Command Injection
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RIESGO
abrir ↗Metasploit600
ManageEngine Multiple Products Authenticated File Upload
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RIESGO
abrir ↗Exploit-DB
phpMyAdmin 4.0.x/4.1.x/4.2.x - Denial of Service
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.7, 4.1.x before 4.1.14.8, and 4.2.x before 4.2.13.1 allows re
28RIESGO
abrir ↗Exploit-DB
GLPI 0.85 - Blind SQL Injection
SQL injection vulnerability in ajax/getDropdownValue.php in GLPI before 0.85.1 allows remote authenticated users to exec
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tuleap - PHP Unserialize Code Execution (Metasploit)
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated
43RIESGO
abrir ↗GitHub PoC★ 2
NTP monlist scanner CVE-2013-5211
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir ↗Exploit-DB
IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Execution
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database
23RIESGO
abrir ↗Exploit-DB
IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Execution
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database
23RIESGO
abrir ↗Metasploit600
WordPress WP Symposium 14.11 Shell Upload
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RIESGO
abrir ↗Exploit-DB
Humhub 0.10.0-rc.1 - SQL Injection
SQL injection vulnerability in the actionIndex function in protected/modules_core/notification/controllers/ListControlle
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenEMR 4.1.2(7) - Multiple SQL Injections
Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execut
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Symposium 14.10 - SQL Injection
SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remo
23RIESGO
abrir ↗Exploit-DB
Advantech AdamView 4.30.003 - '.gni' Local Buffer Overflow (SEH)
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Metasploit300
BMC TrackIt! Unauthenticated Arbitrary User Password Change
BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose na
23RIESGO
abrir ↗Metasploit600
Lexmark MarkVision Enterprise Arbitrary File Upload
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo
60RIESGO
abrir ↗Exploit-DB
PBBoard CMS 3.0.1 - SQL Injection
SQL injection vulnerability in the CheckEmail function in includes/functions.class.php in PBBoard 3.0.1 before 20141128
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kerberos - Privilege Escalation (MS14-068)
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008
100RIESGO
abrir ↗Exploit-DB
Technicolor DT5130 2.05.C29GV - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers t
23RIESGO
abrir ↗Exploit-DB
Technicolor DT5130 2.05.C29GV - Multiple Vulnerabilities
Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metac
23RIESGO
abrir ↗Exploit-DB
Technicolor DT5130 2.05.C29GV - Multiple Vulnerabilities
Open redirect vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to redirect us
23RIESGO
abrir ↗Exploit-DB
Advertise With Pleasure! (AWP) 6.6 - SQL Injection
SQL injection vulnerability in Guruperl.net Advertise With Pleasure! Professional (aka AWP PRO) 6.6 and earlier allows r
23RIESGO
abrir ↗Exploit-DB
ManageEngine Netflow Analyzer / IT360 - Arbitrary File Download
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 a
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.