Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.930exploits catalogados
37.572CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.973GitHub PoC 15.478VulnCheck XDB 9069Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.930 exploits
Metasploit300
Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit300
Qmail SMTP Bash Environment Variable Injection (Shellshock)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit600
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit600
Apache mod_cgi Bash Environment Variable Code Injection (Shellshock)
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir ↗Metasploit300
Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EMC AlphaStor Device Manager Opcode 0x75 - Command Injection (Metasploit)
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote
50RIESGO
abrir ↗Metasploit0
Mac OS X IOKit Keyboard Driver Root Privilege Escalation
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr
98RIESGO
abrir ↗Metasploit300
OS X VMWare Fusion Privilege Escalation via Bash Environment Code Injection (Shellshock)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit300
DHCP Client Bash Environment Variable Code Injection (Shellshock)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit600
Dhclient Bash Environment Variable Injection (Shellshock)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit600
CUPS Filter Bash Environment Variable Code Injection (Shellshock)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit600
CUPS Filter Bash Environment Variable Code Injection (Shellshock)
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir ↗Exploit-DB
Restaurant Script (PizzaInn Project) - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in register-exec.php in Restaurant Script (PizzaInn_Project) 1.0.0 a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advantech Webaccess - dvs.ocx GetColor Buffer Overflow (Metasploit)
Advantech WebAccess Stack-Based Buffer Overflow
68RIESGO
abrir ↗Exploit-DB
webEdition 6.3.8.0 (SVN-Revision: 6985) - Directory Traversal
Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated
43RIESGO
abrir ↗GitHub PoC
Collected fixes for bash CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC
patched-bash-4.3 for CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC★ 6
Patch for CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit500
Adobe Flash Player copyPixelsToByteArray Method Integer Overflow
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LittleSite 0.1 - 'index.php' Local File Inclusion
Directory traversal vulnerability in ls.php in LittleSite (aka LS or LittleSite.php) 0.1 allows remote attackers to incl
23RIESGO
abrir ↗Exploit-DB
M/Monit 3.3.2 - Cross-Site Request Forgery
M/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers
23RIESGO
abrir ↗GitHub PoC★ 46
Research of CVE-2014-3153 and its famous exploit towelroot on x86
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗Exploit-DB
M/Monit 3.3.2 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authe
23RIESGO
abrir ↗Exploit-DB
Livefyre LiveComments Plugin - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗VulnCheck XDB
local
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗Exploit-DB
ClassApps SelectSurvey.net - Multiple SQL Injections
Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Slideshow Gallery 1.4.6 - Arbitrary File Upload
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aztech Routers - '/cgi-bin/AZ_Retrain.cgi' Denial of Service
cgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication,
28RIESGO
abrir ↗Exploit-DB
CacheGuard-OS 5.7.7 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in gui/password-wadmin.apl in CacheGuard OS 5.7.7 allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (1)
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.