Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.003 exploits
Exploit-DB
Skybox Security 6.3.x < 6.4.x - Multiple Denial of Service Vulnerabilities
Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JetAudio 8.1.1 - '.ogg' Crash (PoC)
JetMPAd.ax in JetAudio 8.1.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted .ogg
23RIESGO
abrir ↗Metasploit600
Symantec Workspace Streaming ManagementAgentServer.putFile XMLRPC Request Arbitrary File Upload
The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functional
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Yokogawa CS3000 - 'BKESimmgr.exe' Remote Buffer Overflow (Metasploit)
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
68RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - Shader Buffer Overflow (Metasploit)
Buffer overflow in Adobe Flash Player before 11.7.700.279 and 11.8.x through 13.0.x before 13.0.0.206 on Windows and OS
60RIESGO
abrir ↗Exploit-DB
Alienvault Open Source SIEM (OSSIM) 4.6.1 - (Authenticated) SQL Injection (Metasploit)
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL
43RIESGO
abrir ↗Exploit-DB
VM Turbo Operations Manager 4.5x - Directory Traversal
Directory traversal vulnerability in cgi-bin/help/doIt.cgi in VMTurbo Operations Manager before 4.6 allows remote attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SpiceWorks 7.2.00174 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbi
23RIESGO
abrir ↗Exploit-DB
Skybox Security 6.3.x < 6.4.x - Multiple Information Disclosures
Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly re
23RIESGO
abrir ↗Metasploit300
Belkin Play N750 login.cgi Buffer Overflow
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RIESGO
abrir ↗Metasploit300
AlienVault Authenticated SQL Injection Arbitrary File Read
SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 2.1.3 - '.wav' File Memory Corruption
codec\libpng_plugin.dll in VideoLAN VLC Media Player 2.1.3 allows remote attackers to cause a denial of service (crash)
23RIESGO
abrir ↗GitHub PoC★ 18
cve-2014-0130 rails directory traversal vuln
Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in
83RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TOA - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Open Assessment Technologies TAO 2.5.6 allows remote attackers to hij
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Collabtive 1.2 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Collabtive 1.2 allows remote authenticated users to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Collabtive 1.2 - SQL Injection
SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Exploit-DB
Cobbler 2.4.x < 2.6.x - Local File Inclusion
Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated us
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foscam IP Camera - Predictable Credentials Security Bypass
Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on pred
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Caldera - '/costview2/printers.php?tr' SQL Injection
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Caldera - '/costview2/jobs.php?tr' SQL Injection
Multiple SQL injection vulnerabilities in Caldera 9.20 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - Integer Underflow Remote Code Execution (Metasploit)
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Ma
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NTUserMessageCall Win32k Kernel Pool Overflow 'schlamperei.x86.dll' (MS13-053) (Metasploit)
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RIESGO
abrir ↗Metasploit600
AlienVault OSSIM av-centerd Command Injection
The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a
60RIESGO
abrir ↗Metasploit600
Android 'Towelroot' Futex Requeue Kernel Exploit
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗GitHub PoC★ 15
CVE-2014-0160 (Heartbeat Buffer over-read bug)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts - ClassLoader Manipulation Remote Code Execution (Metasploit)
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.