Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.542VulnCheck XDB 9091Nuclei 4434Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.192 exploits
Exploit-DB
Gnew 2013.1 - Multiple Vulnerabilities (2)
Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir ↗VulnCheck XDB
initial-access
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir ↗Exploit-DB
glibc and eglibc 2.5/2.7/2.13 - Local Buffer Overflow
The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLI
28RIESGO
abrir ↗Exploit-DB
SimpleRisk 20130915-01 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001
23RIESGO
abrir ↗Exploit-DB
mod_accounting Module 0.5 - Blind SQL Injection
SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nodejs - 'js-yaml load()' Code Exec (Metasploit)
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, whic
43RIESGO
abrir ↗Exploit-DB
XAMPP 1.8.1 - 'lang.php?WriteIntoLocalDisk method' Local Write Access
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp
23RIESGO
abrir ↗Exploit-DB
Hewlett-Packard (HP) 2620 Switch Series. Edit Admin Account - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack
23RIESGO
abrir ↗Exploit-DB
X2CRM 3.4.1 - Multiple Vulnerabilities
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and
23RIESGO
abrir ↗Exploit-DB
X2CRM 3.4.1 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗Exploit-DB
Good for Enterprise 2.2.2.1611 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attacker
23RIESGO
abrir ↗Metasploit600
ibstat $PATH Privilege Escalation
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, a
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 6.1/7.1 - Local Privilege Escalation
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, a
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CCaret Use-After-Free (MS13-069) (Metasploit)
Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (
50RIESGO
abrir ↗Metasploit600
Zabbix 2.0.8 SQL Injection and Remote Code Execution
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
60RIESGO
abrir ↗Exploit-DB
WordPress Plugin NOSpamPTI - Blind SQL Injection
SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Theme File Handling - Arbitrary Code Execution (MS13-071) (Metasploit)
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, and Windows Server 2008 SP2 allow remote a
68RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linksys WRT110 - Remote Command Execution (Metasploit)
Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentica
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GLPI - 'install.php' Remote Command Execution (Metasploit)
inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installati
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Lazy SEO 1.1.9 - Arbitrary File Upload
Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers
23RIESGO
abrir ↗Metasploit600
ZeroShell Remote Code Execution
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell meta
60RIESGO
abrir ↗GitHub PoC★ 411
Debian OpenSSL Predictable PRNG (CVE-2008-0166)
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RIESGO
abrir ↗Exploit-DB
vTiger CRM 5.4.0 - 'index.php?onlyforuser' SQL Injection
SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated u
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Complete Gallery Manager 3.3.3 - Arbitrary File Upload
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 r
28RIESGO
abrir ↗Metasploit600
Cisco Prime Data Center Network Manager Arbitrary File Upload
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RIESGO
abrir ↗Metasploit600
F5 iControl Remote Root Command Execution
The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5
50RIESGO
abrir ↗Metasploit300
MS13-080 Microsoft Internet Explorer SetMouseCapture Use-After-Free
Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 throug
100RIESGO
abrir ↗Metasploit0
Astium Remote Code Execution
Astium VOIP PBX <= 2.1 SQL Injection File Upload RCE
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP ProCurve Manager SNAC - UpdateCertificatesServlet Arbitrary File Upload (Metasploit)
UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0,
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sophos Web Protection Appliance - 'sblistpack' Arbitrary Command Execution (Metasploit)
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.