Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB
Seagate BlackArmor NAS - Privilege Escalation
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via s
28RIESGO
abrir ↗Exploit-DB
Taboada Macronews 1.0 - SQL Injection
SQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbi
23RIESGO
abrir ↗Exploit-DB
Technicolor TC7200 - Multiple Cross-Site Request Forgery Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow rem
23RIESGO
abrir ↗Exploit-DB
Nisuta NS-WIR150NE / NS-WIR300N Wireless Routers - Remote Management Web Interface Authentication Bypass
The management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with fi
23RIESGO
abrir ↗Exploit-DB
Technicolor TC7200 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Technicolor (formerly Thomson) TC7200 STD6.01.12 allow remote att
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Libcloud Digital Ocean API - Local Information Disclosure
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows loca
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Advanced Dewplayer - 'download-file.php' Script Directory Traversal
Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CMS Afroditi - 'id' SQL Injection
SQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JForum 'adminUsers' Module - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attack
23RIESGO
abrir ↗Exploit-DB
Huawei Technologies du Mobile Broadband 16.0 - Local Privilege Escalation
Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSIS 'modname' - PHP Code Execution (Metasploit)
Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP cod
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - '.rmp' Version Attribute Buffer Overflow
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat CloudForms Management Engine 5.1 - agent/linuxpkgs Directory Traversal (Metasploit)
Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow re
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP SiteScope issueSiebelCmd - Remote Code Execution (Metasploit)
The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authenti
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology DiskStation Manager - SLICEUPLOAD Remote Command Execution (Metasploit)
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RealNetworks RealPlayer 16.0.3.51/16.0.2.32 - '.rmp' Version Attribute Buffer Overflow
Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738
28RIESGO
abrir ↗Exploit-DB
Huawei Technologies du Mobile Broadband 16.0 - Local Privilege Escalation
Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zimbra Collaboration Server 7.2.2/8.0.2 - Local File Inclusion (Metasploit)
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RIESGO
abrir ↗Exploit-DB
Synology DSM 4.3-3810 - Directory Traversal
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RIESGO
abrir ↗Exploit-DB
Cisco EPC3925 - Persistent Cross-Site Scripting
Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers t
23RIESGO
abrir ↗Exploit-DB
PotPlayer 1.5.40688 - '.avi' File Handling Memory Corruption
PotPlayer 1.5.40688: .avi File Memory Corruption
23RIESGO
abrir ↗Exploit-DB
GOM Player 2.2.56.5158 - '.avi' File Handling Memory Corruption
Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hancom Office - '.hml' File Processing Heap Buffer Overflow
Buffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DenyHosts - 'regex.py' Remote Denial of Service
denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Leed - 'id' SQL Injection
SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to e
23RIESGO
abrir ↗Exploit-DB
Jenkins 1.523 - Persistent HTML Code
Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inj
23RIESGO
abrir ↗Exploit-DB
SonarQube Jenkins Plugin - Plain Text Password
The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (clea
23RIESGO
abrir ↗Exploit-DB
PHP - 'openssl_x509_parse()' Memory Corruption
The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.
35RIESGO
abrir ↗Exploit-DB
Ditto Forensic FieldStation 2013Oct15a - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ndproxy.sys' Local Privilege Escalation (Metasploit)
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.