Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.003 exploits
Exploit-DB
Moodle 2.7 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in user/profile.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DirPHP 1.0 - Local File Inclusion
Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname
23RIESGO
abrir ↗Exploit-DB
ZeroCMS 1.0 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP SP3 - 'MQAC.sys' Arbitrary Write Privilege Escalation (Metasploit)
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir ↗Exploit-DB
Zenoss Monitoring System 4.2.5-2108 (x64) - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Zenoss 4.2.5 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir ↗Exploit-DB
Pligg CMS 2.0.1 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in recover.php in Pligg CMS 2.0.1 and earlier allow remote attackers to execute a
23RIESGO
abrir ↗Metasploit600
Dell SonicWALL Scrutinizer 11.01 methodDetail SQL Injection
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RIESGO
abrir ↗GitHub PoC★ 124
CVE-2014-3153 aka towelroot
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗Exploit-DB
WordPress Plugin Video Gallery 2.5 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin
23RIESGO
abrir ↗VulnCheck XDB
local
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗Exploit-DB
WordPress Plugin Video Gallery 2.5 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ilya Birman E2 - '/@actions/comment-process' SQL Injection
SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the no
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ubiquiti Networks UniFi Video Default - 'crossdomain.xml' Security Bypass
The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVisi
23RIESGO
abrir ↗Metasploit200
MQAC.sys Arbitrary Write Privilege Escalation
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir ↗Exploit-DB
Microsoft Windows XP SP3 - 'BthPan.sys' Arbitrary Write Privilege Escalation
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM GCM16/32 1.20.0.22575 - Multiple Vulnerabilities
prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote aut
23RIESGO
abrir ↗Exploit-DB
Raritan PowerIQ 4.1.0 - SQL Injection (Metasploit)
Multiple SQL injection vulnerabilities in Raritan Power IQ 4.1.0 and 4.2.1 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB
Apache 2.4.7 mod_status - Scoreboard Handling Race Condition
Race condition in the mod_status module in the Apache HTTP Server before 2.4.10 allows remote attackers to cause a denia
45RIESGO
abrir ↗Exploit-DB
Linux Kernel < 3.2.0-23 (Ubuntu 12.04 x64) - 'ptrace/sysret' Local Privilege Escalation
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM GCM16/32 1.20.0.22575 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM GCM16/32 1.20.0.22575 - Multiple Vulnerabilities
systest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote auth
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows XP SP3 - 'MQAC.sys' Arbitrary Write Privilege Escalation
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir ↗Metasploit200
MS14-062 Microsoft Bluetooth Personal Area Networking (BthPan.sys) Privilege Escalation
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir ↗Exploit-DB
ACME micro_httpd - Denial of Service
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 router
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Gallery Objects 0.4 - SQL Injection
SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OL-Commerce - '/OL-Commerce/affiliate_signup.php?a_country' SQL Injection
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OL-Commerce - '/OL-Commerce/admin/create_account.php?entry_country_id' SQL Injection
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fonality trixbox - 'index.php' Directory Traversal
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a ..
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.