Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.192exploits catalogados
37.765CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.138GitHub PoC 15.542VulnCheck XDB 9091Nuclei 4434Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.192 exploits
Metasploit600
Firefox 5.0 - 15.0.1 __exposedProps__ XCS Code Execution
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbi
50RIESGO
abrir ↗Metasploit600
Squash YAML Code Execution
The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter t
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox 5.0 < 15.0.1 - __exposedProps__ XCS Code Execution (Metasploit)
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbi
50RIESGO
abrir ↗Metasploit600
Firefox 5.0 - 15.0.1 __exposedProps__ XCS Code Execution
The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird befo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nmap - Arbitrary File Write
The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote s
23RIESGO
abrir ↗Exploit-DB
StarUML - 'WinGraphviz.dll' ActiveX Buffer Overflow
Buffer overflow in the ToDot method in the WINGRAPHVIZLib.NEATO ActiveX control in WinGraphviz.dll in StarUML allows rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy LAN Folder Share 3.2.0.100 - Local Buffer Overflow (SEH)
Buffer overflow in MostGear Soft Easy LAN Folder Share 3.2.0.100 allows local users to cause a denial of service (applic
23RIESGO
abrir ↗Exploit-DB
RiteCMS 1.0.0 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of
23RIESGO
abrir ↗Exploit-DB
RiteCMS 1.0.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web scri
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PCMan FTP Server 2.07 - 'PASS' Remote Buffer Overflow
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Hyperion 11 - Directory Traversal
Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector - CMD Install Service (Metasploit)
The client in HP Data Protector allows remote attackers to execute arbitrary programs via an EXEC_SETUP command that ref
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows
23RIESGO
abrir ↗Exploit-DB
Western Digital My Net Wireless Routers - Password Disclosure
main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C
23RIESGO
abrir ↗Exploit-DB
vTiger CRM 5.4.0 SOAP - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in vTiger CRM 5.0.0 through 5.4.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - HWND_BROADCAST Low to Medium Integrity Privilege Escalation (MS13-005) (Metasploit)
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ginkgo CMS - 'index.php?rang' SQL Injection
SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang par
23RIESGO
abrir ↗Exploit-DB
SocialEngine Timeline Plugin 4.2.5p9 - Arbitrary File Upload
Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine
23RIESGO
abrir ↗Exploit-DB
vTiger CRM 5.4.0 SOAP - Multiple Vulnerabilities
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models be
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Karotz Smart Rabbit 12.07.19.00 - Multiple Vulnerabilities
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TP-Link TL-SC3171 IP Cameras - Multiple Vulnerabilities
Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MiCasaVerde VeraLite 1.5.408 - Multiple Vulnerabilities
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Karotz Smart Rabbit 12.07.19.00 - Multiple Vulnerabilities
Karotz API 12.07.19.00: Session Token Information Disclosure
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cotonti 0.9.13 - SQL Injection
SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB
vTiger CRM 5.4.0 SOAP - Multiple Vulnerabilities
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote atta
23RIESGO
abrir ↗Exploit-DB
Linux Kernel 3.7.6 (RedHat x86/x64) - 'MSR' Driver Privilege Escalation
The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended ca
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.