Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.842 exploits
Exploit-DB
Filemaker Pro 13.03 / Advanced 12.04 - Authentication Bypass / Privilege Escalation
An Authentication Bypass vulnerability exists in the MatchPasswordData function in DBEngine.dll in Filemaker Pro 13.03 a
23RIESGO
abrir ↗Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Operations Agent - Cross-Site Scripting iFrame Injection
Cross-site scripting (XSS) vulnerability in HP Operations Agent in HP Operations Manager (formerly OpenView Communicatio
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Binary File Descriptor Library (libbfd) - Out-of-Bounds Crash
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
35RIESGO
abrir ↗Exploit-DB
Incredible PBX 2.0.6.5.0 - Remote Command Execution
reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via s
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin CP Multi View Event Calendar 1.01 - SQL Injection
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Centreon - SQL Injection / Command Injection (Metasploit)
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RIESGO
abrir ↗Exploit-DB
CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows r
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin 0.9.7 / Joomla! Component 2.0.0 Creative Contact Form - Arbitrary File Upload
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RIESGO
abrir ↗Exploit-DB
Dell EqualLogic Storage - Directory Traversal
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir ↗Exploit-DB
Magento Server MAGMI Plugin 0.7.17a - Remote File Inclusion
Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a an
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows - OLE Remote Code Execution 'Sandworm' (MS14-060)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir ↗Exploit-DB
Axway Secure Transport 5.1 SP2 - Arbitrary File Upload (via Cross-Site Request Forgery)
Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to
23RIESGO
abrir ↗Exploit-DB
iBackup 10.0.0.32 - Local Privilege Escalation
iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local user
23RIESGO
abrir ↗Metasploit600
Wordpress Creative Contact Form Upload Vulnerability
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery
60RIESGO
abrir ↗Metasploit300
WildFly Directory Traversal
Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.
23RIESGO
abrir ↗Metasploit600
MS14-064 Microsoft Windows OLE Package Manager Code Execution
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Akeeba Kickstart - Unserialize Remote Code Execution (Metasploit)
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeb
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Numara / BMC Track-It! FileStorageService - Arbitrary File Upload (Metasploit)
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbit
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir ↗Exploit-DB
Microsoft Windows - OLE Package Manager SandWorm
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir ↗Exploit-DB
Aireplay-ng 1.2 beta3 - 'tcp_test' Length Stack Overflow
Stack-based buffer overflow in the tcp_test function in aireplay-ng.c in Aircrack-ng before 1.2 RC 1 allows remote attac
28RIESGO
abrir ↗Exploit-DB
Microsoft Windows - OLE Package Manager SandWorm
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux PolicyKit - Race Condition Privilege Escalation (Metasploit)
Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privil
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - OLE Package Manager Code Execution (MS14-060) (Metasploit)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (Add Admin User)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP NetWeaver Enqueue Server - Denial of Service
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of serv
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (2)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 7.0 < 7.31 - 'Drupalgeddon' SQL Injection (PoC) (Reset Password) (1)
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.