Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.842 exploits
Exploit-DB
PHPMyRecipes 1.2.2 - 'dosearch.php?words_exact' SQL Injection
SQL injection vulnerability in dosearch.php in phpMyRecipes 1.2.2 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗Exploit-DB
TRENDnet SecurView Wireless Network Camera TV-IP422WN - 'UltraCamX.ocx' Stack Buffer Overflow (PoC)
Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView ca
28RIESGO
abrir ↗Exploit-DB
Arris VAP2500 - Authentication Bypass
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the confi
23RIESGO
abrir ↗Metasploit300
Arris VAP2500 tools_command.php Command Execution
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authenticatio
50RIESGO
abrir ↗Metasploit300
Arris VAP2500 tools_command.php Command Execution
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute ar
50RIESGO
abrir ↗Metasploit300
Adobe Flash Player PCRE Regex Vulnerability
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RIESGO
abrir ↗Exploit-DB
Arris VAP2500 - Authentication Bypass
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute ar
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin Google Document Embedder 2.5.14 - SQL Injection
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote atta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hikvision DVR - RTSP Request Remote Code Execution (Metasploit)
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RIESGO
abrir ↗Exploit-DB
RobotStats 1.0 - 'robot' SQL Injection
SQL injection vulnerability in the formulaireRobot function in admin/robots.lib.php in RobotStats 1.0 allows remote atta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advantech EKI-6340 - Command Injection
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrar
35RIESGO
abrir ↗Exploit-DB
WordPress Plugin Download Manager 2.7.2 - Privilege Escalation
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users
28RIESGO
abrir ↗Exploit-DB
TP-Link TL-WR740N - Denial of Service
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attack
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows 8.1/ Server 2012 - 'Win32k.sys' Local Privilege Escalation (MS14-058)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir ↗Exploit-DB
RobotStats 1.0 - HTML Injection
Multiple cross-site scripting (XSS) vulnerabilities in admin/robots.lib.php in RobotStats 1.0 allow remote attackers to
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin wpDataTables 1.5.3 - SQL Injection
SQL injection vulnerability in wpdatatables.php in the wpDataTables plugin 1.5.3 and earlier for WordPress allows remote
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin DukaPress 2.5.2 - Directory Traversal
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RIESGO
abrir ↗Exploit-DB
tcpdump 4.6.2 - Geonet Decoder Denial of Service
Multiple Integer underflows in the geonet_print function in tcpdump 4.5.0 through 4.6.2, when in verbose mode, allow rem
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin CM Download Manager 2.0.0 - Code Injection
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plug
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin SP Client Document Manager 2.4.1 - SQL Injection
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu
23RIESGO
abrir ↗Exploit-DB
FluxBB < 1.5.6 - SQL Injection
SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to exe
23RIESGO
abrir ↗Metasploit300
WordPress Long Password DoS
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution / PowerShell VirtualAlloc (MS14-064)
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Metasploit500
HP Performance Monitoring xglance Priv Esc
Unspecified vulnerability in HP Operations Agent 11.00, when Glance is used, allows local users to gain privileges via u
38RIESGO
abrir ↗GitHub PoC★ 3
PowerShell CVE-2014-4113
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir ↗Metasploit300
Hikvision DVR RTSP Request Remote Code Execution
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Paid Memberships Pro 1.7.14.2 - Directory Traversal
Directory traversal vulnerability in services/getfile.php in the Paid Memberships Pro plugin before 1.7.15 for WordPress
28RIESGO
abrir ↗Exploit-DB
Snowfox CMS 1.0 - Cross-Site Request Forgery (Add Admin)
Cross-site request forgery (CSRF) vulnerability in Snowfox CMS before 1.0.10 allows remote attackers to hijack the authe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (2)
The XmlImportExport plugin in MantisBT 1.2.17 and earlier allows remote attackers to execute arbitrary PHP code via a cr
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mantis Bug Tracker 1.2.0a3 < 1.2.17 XmlImportExport Plugin - PHP Code Injection (Metasploit) (1)
The XML Import/Export plugin in MantisBT 1.2.x does not restrict access, which allows remote attackers to (1) upload arb
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.