Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8195Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
3462 exploits
Metasploit300
Ruby on Rails XML Processor YAML Deserialization Scanner
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗Metasploit300
FortiOS Path Traversal Credential Gatherer
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir ↗Metasploit300
Firefox PDF.js Browser File Theft
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RIESGO
abrir ↗Metasploit300
CrushFTP Unauthenticated Arbitrary File Read
Unauthenticated arbitrary file read and remote code execution in CrushFTP
100RIESGO
abrir ↗Metasploit300
Apache Reverse Proxy Bypass Vulnerability Scanner
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RIESGO
abrir ↗Metasploit300
Apache Tomcat User Enumeration
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, al
60RIESGO
abrir ↗Metasploit300
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir ↗Metasploit300
Apache Rave User Information Disclosure
The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain s
60RIESGO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RIESGO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
Android Open Source Platform (AOSP) Browser UXSS
The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribu
23RIESGO
abrir ↗Metasploit300
Android Content Provider File Disclosure
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// UR
43RIESGO
abrir ↗Metasploit300
Adobe ColdFusion Unauthenticated Arbitrary File Read
Adobe ColdFusion Improper Access Control Arbitrary code execution
100RIESGO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RIESGO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RIESGO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RIESGO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RIESGO
abrir ↗Metasploit300
Acronis Cyber Protect/Backup machine info disclosure
Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following
43RIESGO
abrir ↗Metasploit300
Acronis Cyber Protect/Backup machine info disclosure
Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Prot
43RIESGO
abrir ↗Metasploit300
BADPDF Malicious PDF Creator
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier
40RIESGO
abrir ↗Metasploit300
Tomcat Application Manager Login Utility
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RIESGO
abrir ↗Metasploit300
TP-Link Wireless Lite N Access Point Directory Traversal Vulnerability
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13
50RIESGO
abrir ↗Metasploit300
HTTP Cross-Site Tracing Detection
The default configuration of the web server for the Solaris Management Console (SMC) in Solaris 8, 9, and 10 enables the
23RIESGO
abrir ↗Metasploit300
WANGKONGBAO CNS-1000 and 1100 UTM Directory Traversal
Multiple directory traversal vulnerabilities in src/acloglogin.php in Wangkongbao CNS-1000 and 1100 allow remote attacke
50RIESGO
abrir ↗Metasploit300
HTTP WebDAV Internal IP Scanner
IIS 5 and 5.1 supporting WebDAV methods allows remote attackers to determine the internal IP address of the system (whic
30RIESGO
abrir ↗Metasploit300
WordPress XMLRPC GHOST Vulnerability Scanner
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.