Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.023GitHub PoC 13.334VulnCheck XDB 8195Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
3463 exploits
Metasploit300
Emby SSRF HTTP Scanner
Emby Server before 4.5.0 allows SSRF via the Items/RemoteSearch/Image ImageURL parameter.
40RIESGO
abrir ↗Metasploit300
ElasticSearch Snapshot API Directory Traversal
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unsp
60RIESGO
abrir ↗Metasploit300
D-Link DIR-300B / DIR-600B / DIR-815 / DIR-645 HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
Veritas Backup Exec Windows Remote File Access
VERITAS Backup Exec for Windows Servers 8.6 through 10.0, Backup Exec for NetWare Servers 9.0 and 9.1, and NetBackup for
60RIESGO
abrir ↗Metasploit300
D-Link DIR-615H HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
D-Link DIR-300A / DIR-320 / DIR-615D HTTP Login Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
MS09-020 IIS6 WebDAV Unicode Auth Bypass Directory Scanner
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.1 and 6.0 allows remote attackers to bypass URI-
60RIESGO
abrir ↗Metasploit300
MS09-020 IIS6 WebDAV Unicode Auth Bypass Directory Scanner
The WebDAV extension in Microsoft Internet Information Services (IIS) 5.0 on Windows 2000 SP4 does not properly decode U
60RIESGO
abrir ↗Metasploit300
Xymon Daemon Gather Information
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files
23RIESGO
abrir ↗Metasploit300
Dell iDRAC Default Login
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
ColdFusion Server Check
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow re
100RIESGO
abrir ↗Metasploit300
Cambium cnPilot r200/r201 Login Scanner and Config Dump
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, although the option to access the configuration fil
18RIESGO
abrir ↗Metasploit300
Cisco Network Access Manager Directory Traversal Vulnerability
Directory traversal vulnerability in Cisco Network Admission Control (NAC) Manager 4.8.x allows remote attackers to read
23RIESGO
abrir ↗Metasploit300
Cassandra Web File Read Vulnerability
Cassandra Web 0.5.0 - Remote File Read
36RIESGO
abrir ↗Metasploit300
Binom3 Web Management Login Scanner, Config and Password File Dump
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for rem
23RIESGO
abrir ↗Metasploit300
Apache Axis2 Brute Force Utility
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir ↗Metasploit300
Atlassian Crowd XML Entity Expansion Remote File Access
Atlassian JIRA before 5.0.1; Confluence before 3.5.16, 4.0 before 4.0.7, and 4.1 before 4.1.10; FishEye and Crucible bef
50RIESGO
abrir ↗Metasploit300
Apache "mod_userdir" User Enumeration
Apache on Red Hat Linux with with the UserDir directive enabled generates different error codes when a username exists a
50RIESGO
abrir ↗Metasploit300
Apache ActiveMQ Directory Traversal
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP
60RIESGO
abrir ↗Metasploit300
Apache ActiveMQ JSP Files Source Disclosure
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP
60RIESGO
abrir ↗Metasploit300
Adobe XML External Entity Injection
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service
100RIESGO
abrir ↗Metasploit300
FTP Authentication Scanner
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
DNS Amplification Scanner
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive querie
30RIESGO
abrir ↗Metasploit300
DNS Amplification Scanner
The default configuration of the DNS Server service on Windows Server 2003 and Windows 2000, and the Microsoft DNS Serve
30RIESGO
abrir ↗Metasploit300
DB2 Authentication Brute Force Utility
A Unix account has a default, null, blank, or missing password.
50RIESGO
abrir ↗Metasploit300
CouchDB Enum Utility
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir ↗Metasploit300
Apple Airport ACPP Authentication Scanner
The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fi
23RIESGO
abrir ↗Metasploit300
Energizer DUO Trojan Scanner
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Aru
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.