Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.405exploits catalogados
37.905CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.237GitHub PoC 15.606VulnCheck XDB 9133Nuclei 4441Metasploit 3506✓ solo verificadosrecientespopularesriesgo
81.407 exploits
Metasploit600
Ruby on Rails XML Processor YAML Deserialization Code Execution
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir ↗Exploit-DB
Ettercap 0.7.5.1 - Stack Overflow
Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow loc
23RIESGO
abrir ↗Metasploit300
Foxit Reader Plugin URL Processing Buffer Overflow
Foxit Reader <= 5.4.5.0114 Plugin URL Processing Buffer Overflow
43RIESGO
abrir ↗Metasploit600
Movable Type 4.2x, 4.3x Web Upgrade Remote Code Execution
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for reque
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Movable Type 4.2x/4.3x - Web Upgrade Remote Code Execution (Metasploit)
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Havalite CMS - 'comment' HTML Injection
Havalite CMS 1.1.7 has a stored XSS vulnerability
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nexpose Security Console - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Enterasys NetSight - 'nssyslogd.exe' Remote Buffer Overflow (Metasploit)
Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1
60RIESGO
abrir ↗Metasploit300
WordPress Plugin Google Document Embedder Arbitrary File Disclosure
Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers t
50RIESGO
abrir ↗Metasploit300
Simple Web Server 2.3-RC1 Directory Traversal
Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Belkin Wireless Router - Default WPS PIN Security
Belkin wireless routers Surf N150 Model F7D1301v1, N900 Model F9K1104v1, N450 Model F9K1105V2, and N300 Model F7D2301v1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CButton Object Use-After-Free (Metasploit)
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
e107 1.0.1 - Arbitrary JavaScript Execution (via Cross-Site Request Forgery)
Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hija
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
e107 1.0.2 - SQL Injection (via Cross-Site Request Forgery)
Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - CDwnBindInfo Object Use-After-Free (Metasploit)
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus QuickR qp2 - ActiveX Buffer Overflow (Metasploit)
Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-00
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BlazeDVD 6.1 - '.PLF' File (ASLR + DEP Bypass) (Metasploit)
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RIESGO
abrir ↗Metasploit600
eXtplorer v2.1 Arbitrary File Upload Vulnerability
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empt
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Grep < 2.11 - Integer Overflow Crash (PoC)
Multiple integer overflows in GNU Grep before 2.11 might allow context-dependent attackers to execute arbitrary code via
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus iNotes dwa85W - ActiveX Buffer Overflow (Metasploit)
Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x befo
43RIESGO
abrir ↗Metasploit0
MoinMoin twikidraw Action Traversal File Upload
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action
50RIESGO
abrir ↗Metasploit600
Wordpress Reflex Gallery Upload Vulnerability
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RIESGO
abrir ↗GitHub PoC★ 1
Mempodipper, a linux local root exploit.
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RIESGO
abrir ↗VulnCheck XDB
local
The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RealPlayer - '.RealMedia' File Handling Buffer Overflow (Metasploit)
Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers
50RIESGO
abrir ↗Metasploit300
MS13-008 Microsoft Internet Explorer CButton Object Use-After-Free Vulnerability
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus Notes Client URL Handler - Command Injection (Metasploit)
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted
50RIESGO
abrir ↗Metasploit200
Nvidia (nvsvc) Display Driver Service Local Privilege Escalation
The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.