Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.270 exploits
Metasploit500
AdobeCollabSync Buffer Overflow Adobe Reader X Sandbox Bypass
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attacke
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ERS Viewer 2011 - '.ERS' File Handling Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 1
43RIESGO
abrir ↗Exploit-DB
Linux Kernel 2.6.32 < 3.x (CentOS 5/6) - 'PERF_EVENTS' Local Privilege Escalation (1)
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir ↗Exploit-DB
Linux Kernel < 3.8.x - open-time Capability 'file_ns_capable()' Local Privilege Escalation
kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_m
23RIESGO
abrir ↗GitHub PoC★ 1
This is used to scan for CVE-2012-2122 vulnerable servers.
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MoinMoin - Arbitrary Command Execution
Multiple directory traversal vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action/anyw
28RIESGO
abrir ↗Exploit-DB
ColdFusion 9-10 - Credential Disclosure
Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MoinMoin - Arbitrary Command Execution
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action
50RIESGO
abrir ↗Exploit-DB
Huawei SNMPv3 Service - Multiple Buffer Overflow Vulnerabilities (PoC)
Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 is enabled, allow remote attackers to cause a denial of se
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetApp OnCommand System Manager - '/zapiServlet' User Management Interface Multiple Cross-Site Scripting Vulnerabilities
Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB
Cisco Linksys E4200 - Multiple Vulnerabilities
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to
28RIESGO
abrir ↗Metasploit500
Nginx HTTP Server 1.3.9-1.4.0 Chunked Encoding Stack Buffer Overflow
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir ↗Exploit-DB
Cisco Linksys E4200 - Multiple Vulnerabilities
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Metasploit300
ColdFusion 'password.properties' Hash Extraction
Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files
60RIESGO
abrir ↗Exploit-DB
Cisco Linksys E4200 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow rem
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetApp OnCommand System Manager - '/zapiServlet' CIFS Configuration Management Interface Multiple Cross-Site Scripting Vulnerabilities
Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
b2evolution 4.1.6 - Multiple Vulnerabilities
SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to
23RIESGO
abrir ↗Exploit-DB
Cisco Linksys E4200 - Multiple Vulnerabilities
Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers
28RIESGO
abrir ↗Exploit-DB
Huawei SNMPv3 Service - Multiple Buffer Overflow Vulnerabilities (PoC)
Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CGenericElement Object Use-After-Free (Metasploit)
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit
100RIESGO
abrir ↗Exploit-DB
Cisco Linksys E4200 - Multiple Vulnerabilities
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers
28RIESGO
abrir ↗Exploit-DB
Cisco Linksys E4200 - Multiple Vulnerabilities
Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain
23RIESGO
abrir ↗Exploit-DB
Cisco Linksys E4200 - Multiple Vulnerabilities
Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive in
23RIESGO
abrir ↗Metasploit400
MS13-038 Microsoft Internet Explorer CGenericElement Object Use-After-Free Vulnerability
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit
100RIESGO
abrir ↗Metasploit300
AudioCoder .M3U Buffer Overflow
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin - 'preg_replace' (Authenticated) Remote Code Execution (Metasploit)
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin W3 Total Cache - PHP Code Execution (Metasploit)
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link IP Cameras - Multiple Vulnerabilities
An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.0
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link IP Cameras - Multiple Vulnerabilities
An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processin
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WPS Office - 'Wpsio.dll' Stack Buffer Overflow
Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to exec
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.