Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.270 exploits
Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RIESGO
abrir ↗Metasploit300
OpenSSL TLS 1.1 and 1.2 AES-NI DoS
crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 bef
30RIESGO
abrir ↗Metasploit600
Linksys E1500/E2500 apply.cgi Remote Command Injection
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version
41RIESGO
abrir ↗Metasploit300
Linksys E1500/E2500 Remote Command Execution
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Samsung Kies Air 2.1.207051 and 2.1.210161 relies on the IP address for authentication, which allows remote man-in-the-m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Unity Express - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow rem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Portable UPnP SDK - 'unique_service_name()' Remote Code Execution (Metasploit)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
35RIESGO
abrir ↗Metasploit600
D-Link Devices Unauthenticated Remote Command Execution
D-Link Devices command.php Unauthenticated RCE
68RIESGO
abrir ↗Metasploit300
D-Link DIR-600 / DIR-300 Unauthenticated Remote Command Execution
D-Link Devices Unauthenticated RCE
68RIESGO
abrir ↗Metasploit0
Raidsonic NAS Devices Unauthenticated Remote Command Execution
Raidsonic NAS Devices Unauthenticated Remote Command Execution
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CADA 3S CoDeSys Gateway Server - Directory Traversal (Metasploit)
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitr
50RIESGO
abrir ↗Metasploit600
SCADA 3S CoDeSys Gateway Server Directory Traversal
Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitr
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DataLife Engine - 'preview.php' PHP Code Injection (Metasploit)
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/pr
50RIESGO
abrir ↗Metasploit600
D-Link Unauthenticated Remote Command Execution using UPnP via a special crafted M-SEARCH packet.
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled b
23RIESGO
abrir ↗Metasploit600
D-Link Unauthenticated Remote Command Execution using UPnP via a special crafted M-SEARCH packet.
D-Link DIR-600 Hardware Version B5, Firmware Version 2.18 was discovered to contain a command injection vulnerability vi
30RIESGO
abrir ↗Metasploit600
D-Link Unauthenticated Remote Command Execution using UPnP via a special crafted M-SEARCH packet.
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DataLife Engine - 'preview.php' PHP Code Injection (Metasploit)
Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Firebird - Relational Database CNCT Group Number Buffer Overflow (Metasploit)
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Audio Player - 'playerID' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress al
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Groupwise Client 8.0 - Multiple Remote Code Execution Vulnerabilities
The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary
28RIESGO
abrir ↗Metasploit300
Firebird Relational Database CNCT Group Number Buffer Overflow
Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windo
50RIESGO
abrir ↗Metasploit300
Novell GroupWise Client gwcls1.dll ActiveX Remote Code Execution
An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows r
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Multiple Hunt CCTV - Information Disclosure
Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Wel
60RIESGO
abrir ↗GitHub PoC★ 2
heroku/heroku-CVE-2013-0333
lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.