Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
pfSense 2.2 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before
35RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
RM Downloader 2.7.5.400 - Local Buffer Overflow
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB
WebGate eDVR Manager - Remote Stack Buffer Overflow
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Exploit-DB
QNAP - Web Server Remote Code Execution via Bash Environment Variable Code Injection (Metasploit)
Multiple unspecified vulnerabilities in Google Chrome before 39.0.2171.65 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Exploit-DB
QNAP - Admin Shell via Bash Environment Variable Code Injection (Metasploit)
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RIESGO
abrir ↗Exploit-DB
Adobe Flash Player - Arbitrary Code Execution
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Remote Code Execution (Add Admin)
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - Proxy Prototype Privileged JavaScript Injection (Metasploit)
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote auth
35RIESGO
abrir ↗Exploit-DB
WordPress Plugin Marketplace 2.4.0 - Arbitrary File Download
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin b
28RIESGO
abrir ↗Exploit-DB
Telescope 0.9.2 - Markdown Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary
23RIESGO
abrir ↗Exploit-DB
Joomla! Component ECommerce-WD 1.2.5 - SQL Injection
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component 1.2.5 for Joomla! allo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TWiki Debugenableplugins - Remote Code Execution (Metasploit)
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RIESGO
abrir ↗Exploit-DB
Citrix Command Center - Credential Disclosure
Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 allows remote attackers to obtain credentials via
28RIESGO
abrir ↗Exploit-DB
EMC M&R (Watch4net) - Credential Disclosure
EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-cen
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.