Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.842 exploits
Exploit-DB✓ VexDay Proof
Microsoft Bluetooth Personal Area Networking - 'BthPan.sys' Local Privilege Escalation (Metasploit)
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir ↗Metasploit600
Centreon SQL and Command Injection
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RIESGO
abrir ↗Metasploit600
Centreon SQL and Command Injection
Multiple SQL injection vulnerabilities in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3
60RIESGO
abrir ↗Metasploit600
Drupal HTTP Parameter Key/Value SQL Injection
The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Centreon < 2.5.1 / Centreon Enterprise Server < 2.2 - SQL Injection / Command Injection (Metasploit)
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remot
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
YourMembers Plugin - Blind SQL Injection
SQL injection vulnerability in includes/ym-download_functions.include.php in the Code Futures YourMembers plugin for Wor
23RIESGO
abrir ↗Exploit-DB
Croogo 2.0.0 - Multiple Persistent Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB
Tenda A32 Router - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN a
23RIESGO
abrir ↗Metasploit300
SSL/TLS Version Detection
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which mak
45RIESGO
abrir ↗Metasploit300
Windows TrackPopupMenu Win32k NULL Pointer Dereference
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir ↗Metasploit600
MS14-060 Microsoft Windows OLE Package Manager Code Execution
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir ↗Metasploit300
SSL/TLS Version Detection
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for
50RIESGO
abrir ↗Metasploit300
SSL/TLS Version Detection
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefo
40RIESGO
abrir ↗Metasploit500
Adobe Flash Player casi32 Integer Overflow
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and bef
60RIESGO
abrir ↗Metasploit300
SSL/TLS Version Detection
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to se
40RIESGO
abrir ↗Metasploit300
SSL/TLS Version Detection
Using a Custom Cipher with NID_undef may lead to NULL encryption
18RIESGO
abrir ↗Metasploit300
SSL/TLS Version Detection
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not pro
45RIESGO
abrir ↗GitHub PoC★ 10
Exploit for CVE-2014-7236
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RIESGO
abrir ↗Exploit-DB
CMS Made Simple 1.11.9 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in CMS Made Simple allow remote authenticated users to inject arbitr
23RIESGO
abrir ↗Exploit-DB
GetSimple CMS 3.3.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.3.1 allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB
Pimcore CMS 1.4.9 <2.1.0 - Multiple Vulnerabilities
The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.0.0 doe
23RIESGO
abrir ↗Exploit-DB
Pimcore CMS 1.4.9 <2.1.0 - Multiple Vulnerabilities
The getObjectByToken function in Newsletter.php in the Pimcore_Tool_Newsletter module in pimcore 1.4.9 through 2.1.0 doe
23RIESGO
abrir ↗Exploit-DB
vBulletin 4.x/5.x - AdminCP/ApiLog via xmlrpc API (Authenticated) Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admincp/apilog.php in vBulletin 4.2.2 and earlier, and 5.0.x through 5.0.5 a
23RIESGO
abrir ↗Exploit-DB
vBulletin 4.x - breadcrumbs via xmlrpc API (Authenticated) SQL Injection
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier a
23RIESGO
abrir ↗GitHub PoC★ 1
Heartbleed (CVE-2014-0160) SSLv3 Scanner
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB
BMC Track-It! - Multiple Vulnerabilities
BMC Track-It! 11.3.0.355 allows remote authenticated users to read arbitrary files by visiting the TrackItWeb/Attachment
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin InfusionSoft - Arbitrary File Upload (Metasploit)
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nessus Web UI 2.3.3 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web s
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rejetto HTTP File Server (HFS) - Remote Command Execution (Metasploit)
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.