Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.064 exploits
Metasploit300
Apache Commons FileUpload and Apache Tomcat DoS
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products,
60RIESGO
abrir ↗GitHub PoC★ 8
Android Data Stealing Vulnerability
The Android browser in Android before 2.3.4 allows remote attackers to obtain SD card contents via crafted content:// UR
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat Manager - Application Upload (Authenticated) Code Execution (Metasploit)
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RIESGO
abrir ↗Metasploit300
Publish-It PUI Buffer Overflow (SEH)
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir ↗Metasploit300
Adobe Flash Player Integer Underflow Remote Code Execution
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Ma
100RIESGO
abrir ↗Exploit-DB
ownCloud 6.0.0a - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in ownCloud before 6.0.1 allows remote authenticated users to inject arbitrary
23RIESGO
abrir ↗Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Skybluecanvas CMS - Remote Code Execution (Metasploit)
The bashMail function in cms/data/skins/techjunkie/fragments/contacts/functions.php in SkyBlueCanvas CMS before 1.1 r248
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XnView 1.92.1 - Command-Line Arguments Buffer Overflow
Buffer overflow in XnView 1.92.1 allows user-assisted remote attackers to execute arbitrary code via a long filename arg
28RIESGO
abrir ↗Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts - Developer Mode OGNL Execution (Metasploit)
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RIESGO
abrir ↗Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
D-Link DIR-100 4.03B07: cli.cgi CSRF
23RIESGO
abrir ↗Exploit-DB
VideoLAN VLC Media Player 2.1.2 - '.asf' Crash (PoC)
The ASF_ReadObject_file_properties function in modules/demux/asf/libasf.c in the ASF Demuxer in VideoLAN VLC Media Playe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ImpressCMS 1.3.5 - Multiple Vulnerabilities
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows
23RIESGO
abrir ↗Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
28RIESGO
abrir ↗Exploit-DB
D-Link DIR-100 - Multiple Vulnerabilities
D-Link DIR-100 4.03B07: cli.cgi XSS
23RIESGO
abrir ↗Exploit-DB
TopicsViewer 3.0 Beta 1 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/reboot.cgi' Remote Reboot (Denial of Service)
cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) v
23RIESGO
abrir ↗Metasploit600
Array Networks vAPV and vxAG Private Key Privilege Escalation Code Execution
Array Networks vAPV and vxAG Default Credential Privilege Escalation
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seowon Intech WiMAX SWC-9100 Router - '/cgi-bin/diagnostic.cgi?ping_ipaddr' Remote Code Execution
The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.04/13.10 x64) - 'CONFIG_X86_X32=y' Local Privilege Escalation (3)
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir ↗GitHub PoC★ 199
Linux local root exploit for CVE-2014-0038
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir ↗Metasploit400
Linux Kernel recvmmsg Privilege Escalation
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.4 < 3.13.2 (Ubuntu 13.10) - 'CONFIG_X86_X32' Arbitrary Write (2)
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MediaWiki 1.22.1 PdfHandler - Remote Code Execution
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RIESGO
abrir ↗Metasploit600
Pandora FMS Default Credential / SQLi Remote Code Execution
Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE
63RIESGO
abrir ↗Exploit-DB
Linux Kernel 3.4 < 3.13.2 - recvmmsg x32 compat (PoC)
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RIESGO
abrir ↗Metasploit600
Zpanel Remote Unauthenticated RCE
ZPanel through 10.1.0 has Remote Command Execution
43RIESGO
abrir ↗Metasploit600
Pandora FMS Remote Code Execution
Pandora FMS <= 5.0RC1 Anyterm Unauthenticated Command Injection
63RIESGO
abrir ↗Exploit-DB
Oracle Forms and Reports 11.1 - Arbitrary Code Execution
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.