Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.064 exploits
Exploit-DB✓ VexDay Proof
Light Alloy 4.7.3 - '.m3u' Local Buffer Overflow (SEH Unicode)
Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a l
23RIESGO
abrir ↗Metasploit300
Ruby on Rails JSON Processor Floating Point Heap Overflow DoS
Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and tru
30RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Thomson Reuters Velocity Analytics - Remote Code Injection
VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PineApp MailSecure - Remote Command Execution
PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PineApp MailSecure - Remote Command Execution
admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacha
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PineApp MailSecure - Remote Command Execution
admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DeepOfix SMTP Server 3.3 - Authentication Bypass
The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, whic
23RIESGO
abrir ↗Metasploit600
Idera Up.Time Monitoring Station 7.0 post2file.php Arbitrary File Upload
Idera Up.Time ≤ 7.2 post2file.php Arbitrary File Upload RCE
63RIESGO
abrir ↗Exploit-DB
Ruckus Wireless Zoneflex 2942 Wireless Access Point - Authentication Bypass
Ruckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and sub
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nginx 1.1.17 - URI Processing SecURIty Bypass
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescap
35RIESGO
abrir ↗Exploit-DB
LiveZilla 5.0.1.4 - Remote Code Execution
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Supermicro Onboard IPMI - 'close_window.cgi' Remote Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Managemen
60RIESGO
abrir ↗Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access
23RIESGO
abrir ↗GitHub PoC★ 27
CVE-2013-6282 exploit
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir ↗Exploit-DB
ManageEngine Desktop Central 8.0.0 build < 80293 - Arbitrary File Upload
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before buil
60RIESGO
abrir ↗Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent
23RIESGO
abrir ↗Exploit-DB
ManageEngine Desktop Central 8.0.0 build < 80293 - Arbitrary File Upload
Directory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop
35RIESGO
abrir ↗Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RIESGO
abrir ↗Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to o
23RIESGO
abrir ↗Exploit-DB
Dahua DVR 2.608.0000.0/2.608.GV00.0 - Authentication Bypass (Metasploit)
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Watermark Master 2.2.23 - '.wstyle' Local Buffer Overflow (SEH)
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Testa OTMS - Multiple SQL Injections
SQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arb
23RIESGO
abrir ↗Exploit-DB
TOSHIBA e-Studio 232/233/282/283 - Cross-Site Request Forgery (Change Admin Password)
Cross-site request forgery (CSRF) vulnerability in TopAccess (aka the web-based management utility) on TOSHIBA TEC e-Stu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Altiris DS - SQL Injection (Metasploit)
SQL injection vulnerability in axengine.exe in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allow
50RIESGO
abrir ↗Exploit-DB
ALLPlayer 5.6.2 - '.m3u' File Local Buffer Overflow (SEH Unicode)
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir ↗Exploit-DB
Juniper Junos J-Web - Privilege Escalation
jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3,
28RIESGO
abrir ↗Metasploit300
Red Hat CloudForms Management Engine 5.1 miq_policy/explorer SQL Injection
SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and Mana
23RIESGO
abrir ↗Metasploit600
Kaseya uploadImage Arbitrary File Upload
Kaseya < 6.3.0.2 uploadImage.asp Arbitrary File Upload RCE
63RIESGO
abrir ↗Metasploit300
Huawei Datacard Information Disclosure Vulnerability
The Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remot
18RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.