Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8195Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
3462 exploits
Metasploit300
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir ↗Metasploit300
MSSQL Login Utility
A Windows NT domain user or administrator account has a default, null, blank, or missing password.
23RIESGO
abrir ↗Metasploit300
Novell ZENworks Configuration Management Preboot Service Remote File Access
Directory traversal vulnerability in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1
23RIESGO
abrir ↗Metasploit300
EasyCafe Server Remote File Access
EasyCafe Server 2.2.14 Remote File Disclosure via Opcode 0x43
36RIESGO
abrir ↗Metasploit300
Multiple DVR Manufacturers Configuration Disclosure
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Wel
60RIESGO
abrir ↗Metasploit300
Dahua DVR Auth Bypass Scanner
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
60RIESGO
abrir ↗Metasploit300
CrushFTP Unauthenticated Arbitrary File Read
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗Metasploit300
cups-browsed Information Disclosure
cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source
60RIESGO
abrir ↗Metasploit300
Lotus Domino Password Hash Collector
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.n
43RIESGO
abrir ↗Metasploit300
Novell ZENworks Asset Management 7.5 Configuration Access
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username o
30RIESGO
abrir ↗Metasploit300
Novell ZENworks Asset Management 7.5 Remote File Access
The rtrlet web application in the Web Console in Novell ZENworks Asset Management (ZAM) 7.5 uses a hard-coded username o
30RIESGO
abrir ↗Metasploit300
Firefox PDF.js Browser File Theft
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RIESGO
abrir ↗Metasploit300
WordPress Subscribe Comments File Read Vulnerability
Subscribe to Comments <= 2.1.2 - Local File Includion
36RIESGO
abrir ↗Metasploit300
FortiOS Path Traversal Credential Gatherer
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir ↗Metasploit300
WordPress Simple Backup File Read Vulnerability
Simple Backup <= 2.7.10 - Arbitrary File Download via Path Traversal
36RIESGO
abrir ↗Metasploit300
WordPress NextGEN Gallery Directory Read Vulnerability
The NextGEN Gallery plugin before 2.1.15 for WordPress allows ../ Directory Traversal in path selection.
23RIESGO
abrir ↗Metasploit300
WordPress Mobile Edition File Read Vulnerability
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary
30RIESGO
abrir ↗Metasploit300
WordPress Mobile Pack Information Disclosure Vulnerability
The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected post
23RIESGO
abrir ↗Metasploit300
WordPress GI-Media Library Plugin Directory Traversal Vulnerability
GI-Media Library < 3.0 - Directory Traversal
36RIESGO
abrir ↗Metasploit300
WordPress DukaPress Plugin File Read Vulnerability
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RIESGO
abrir ↗Metasploit300
Wordpress XML-RPC Username/Password Login Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
Wordpress Pingback Locator
The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct
23RIESGO
abrir ↗Metasploit300
WordPress Brute Force and User Enumeration Utility
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the u
60RIESGO
abrir ↗Metasploit300
WordPress XMLRPC GHOST Vulnerability Scanner
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir ↗Metasploit300
HTTP WebDAV Internal IP Scanner
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (whic
30RIESGO
abrir ↗Metasploit300
ManageEngine ADAudit Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RIESGO
abrir ↗Metasploit300
ManageEngine DataSecurity Plus Xnode Enumeration
Zoho ManageEngine DataSecurity Plus prior to 6.0.1 uses default admin credentials to communicate with a DataEngine Xnode
40RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.