Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.003 exploits
Exploit-DB
WordPress Plugin Slideshow Gallery 1.4.6 - Arbitrary File Upload
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RIESGO
abrir ↗Exploit-DB
ManageEngine Desktop Central - Arbitrary File Upload / Remote Code Execution
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
28RIESGO
abrir ↗Exploit-DB
ManageEngine Desktop Central - Arbitrary File Upload / Remote Code Execution
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
60RIESGO
abrir ↗Exploit-DB
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (1)
ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mulitple WordPress Themes - 'admin-ajax.php?img' Arbitrary File Download
Directory traversal vulnerability in the Slider Revolution (revslider) plugin before 4.2 for WordPress allows remote att
28RIESGO
abrir ↗Exploit-DB
ManageEngine Desktop Central - Arbitrary File Upload / Remote Code Execution
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RIESGO
abrir ↗Exploit-DB
ManageEngine EventLog Analyzer - Multiple Vulnerabilities (1)
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8
60RIESGO
abrir ↗Exploit-DB
ManageEngine Desktop Central - Arbitrary File Upload / Remote Code Execution
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wing FTP Server - (Authenticated) Command Execution (Metasploit)
20RIESGO
abrir ↗Metasploit600
ManageEngine Eventlog Analyzer Arbitrary File Upload
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8
60RIESGO
abrir ↗Metasploit600
ManageEngine Desktop Central StatusUpdate Arbitrary File Upload
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
60RIESGO
abrir ↗Exploit-DB
F5 Big-IP - rsync Access
The rsync daemon in F5 BIG-IP 11.6 before 11.6.0, 11.5.1 before HF3, 11.5.0 before HF4, 11.4.1 before HF4, 11.4.0 before
23RIESGO
abrir ↗Exploit-DB
NRPE 2.15 - Remote Code Execution
Incomplete blacklist vulnerability in nrpe.c in Nagios Remote Plugin Executor (NRPE) 2.15 and earlier allows remote atta
28RIESGO
abrir ↗Exploit-DB
PhpWiki - Remote Command Execution
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a dev
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin ShortCode 0.2.3 - Local File Inclusion
Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress
28RIESGO
abrir ↗Exploit-DB
XRms - Blind SQL Injection / Command Execution
SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB
Microsoft Internet Explorer - Memory Corruption (PoC) (MS14-029)
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - WebIDL Privileged JavaScript Injection (Metasploit)
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and Se
60RIESGO
abrir ↗Exploit-DB
ManageEngine DeviceExpert 5.9 - User Credential Disclosure
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user acc
50RIESGO
abrir ↗Metasploit300
ManageEngine DeviceExpert User Credentials
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user acc
50RIESGO
abrir ↗Metasploit600
Wordpress SlideShow Gallery Authenticated File Upload
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RIESGO
abrir ↗Metasploit600
ActualAnalyzer 'ant' Cookie Command Execution
Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for pa
68RIESGO
abrir ↗Exploit-DB
Plogger 1.0-RC1 - (Authenticated) Arbitrary File Upload
Unrestricted file upload vulnerability in plog-admin/plog-upload.php in Plogger 1.0 RC1 and earlier allows remote authen
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - WebIDL Privileged JavaScript Injection (Metasploit)
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remo
60RIESGO
abrir ↗Exploit-DB
XRms - Blind SQL Injection / Command Execution
plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
glibc - NUL Byte gconv_translit_find Off-by-One
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-depe
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Granding MA300 - Traffic Sniffing Man In The Middle Fingerprint PIN Disclosure
Grand MA 300 allows retrieval of the access PIN from sniffed data.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Granding MA300 - Weak Pin Encryption Brute Force
Grand MA 300 allows a brute-force attack on the PIN.
23RIESGO
abrir ↗Metasploit600
Railo Remote File Include
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cf
50RIESGO
abrir ↗Exploit-DB
ntopng 1.2.0 - Cross-Site Scripting Injection
Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 al
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.