Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.270 exploits
Exploit-DB✓ VexDay Proof
WordPress Plugin NextGEN Gallery - Full Path Disclosure
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
28RIESGO
abrir ↗Metasploit200
MS13-009 Microsoft Internet Explorer SLayoutRun Use-After-Free
Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a cr
50RIESGO
abrir ↗Metasploit600
OpenEMR PHP File Upload Vulnerability
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenEMR 4.1.1 - 'ofc_upload_image.php' Arbitrary File Upload
Unrestricted file upload vulnerability in ofc_upload_image.php in Open Flash Chart v2 Beta 1 through v2 Lug Wyrm Charmer
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenEMR 4.1.1 - 'ofc_upload_image.php' Arbitrary File Upload
Multiple cross-site scripting (XSS) vulnerabilities in iTop (aka IT Operations Portal) 1.1.181 and 1.2.0-RC-282 allow re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Groupwise Client - 'gwcls1.dll' ActiveX Remote Code Execution (Metasploit)
An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows r
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware OVF Tools - Format String (Metasploit) (2)
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RIESGO
abrir ↗Exploit-DB
cURL - Buffer Overflow (PoC)
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7
28RIESGO
abrir ↗Exploit-DB
Microsoft Windows - HWND_BROADCAST (PoC) (MS13-005)
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7
43RIESGO
abrir ↗Metasploit600
Linksys WRT160nv2 apply.cgi Remote Command Injection
Linksys Routers apply.cgi Remote Command Injection
36RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linksys E1500/E2500 - Multiple Vulnerabilities
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers
28RIESGO
abrir ↗Exploit-DB
Linksys WRT160N - Multiple Vulnerabilities
Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Schneider Electric Accutech Manager - Heap Overflow (PoC)
Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remo
28RIESGO
abrir ↗GitHub PoC★ 3
MySQL-Fu is a Ruby based MySQL Client Script I wrote. It does most of the stuff a normal MySQL client might do: SQL Shell, Update/Delete/Drop Database/Table, Add/Delete Users, Dump Database(s)/Table w/ option for gzip...... Plus a few extra options to make life a little easier for pentests. Includes Several builtin PHP Command Shell options as well as Pentestmonkey's PHP Reverse Shell, in addition to multiple options for file writing and reading (all files read logged locally for offline analysis later), also includes Ruby port of Kingcope's CVE-2012-5613 Linux MySQL Privilege Escalation Exploit.
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗Metasploit300
D-Link hedwig.cgi Buffer Overflow in Cookie Header
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allo
43RIESGO
abrir ↗Metasploit300
Adobe Flash Player Regular Expression Heap Overflow
Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x
60RIESGO
abrir ↗Metasploit300
D-Link authentication.cgi Buffer Overflow
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allo
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CubeCart 5.2.0 - 'cubecart.class.php' PHP Object Injection
The Cubecart::_basket method in classes/cubecart.class.php in CubeCart 5.0.0 through 5.2.0 allows remote attackers to un
23RIESGO
abrir ↗Metasploit600
D-Link DIR615h OS Command Injection
D-Link Routers tools_vct.htm OS Command Injection
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cool PDF Reader 3.0.2.256 - Buffer Overflow
Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a P
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Wysija Newsletters - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenti
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware OVF Tools - Format String (Metasploit) (1)
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RIESGO
abrir ↗Metasploit600
Netgear DGN1000B setup.cgi Remote Command Execution
Netgear Routers setup.cgi RCE
36RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin CommentLuv - '_ajax_nonce' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to
23RIESGO
abrir ↗Exploit-DB
Linux Kernel 2.6.32-5 (Debian 6.0.5) - '/dev/ptmx' Key Stroke Timing Local Disclosure
The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the in
23RIESGO
abrir ↗Exploit-DB
FreeBSD 9.1 - 'ftpd' Remote Denial of Service
The glob implementation in Pure-FTPd before 1.0.32, and in libc in NetBSD 5.1, does not properly expand expressions cont
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RIESGO
abrir ↗Metasploit300
OpenSSL TLS 1.1 and 1.2 AES-NI DoS
crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 bef
30RIESGO
abrir ↗Metasploit600
Glossword v1.8.8 - 1.8.12 Arbitrary File Upload Vulnerability
Glossword 1.8.8 - 1.8.12 Arbitrary File Upload RCE
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.