Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.106exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 22.936GitHub PoC 15.009VulnCheck XDB 8846Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
OP5 5.3.5/5.4.0/5.4.2/5.5.0/5.5.1 - 'license.php' Remote Command Execution (Metasploit)
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execu
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ManageEngine (Multiple Products) - (Authenticated) Arbitrary File Upload (Metasploit)
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX networkd - 'effective_audit_token' XPC Type Confusion Sandbox Escape
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows < 8.1 (x86/x64) - User Profile Service Privilege Escalation (MS15-003)
The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lexmark MarkVision Enterprise - Arbitrary File Upload (Metasploit)
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle MySQL (Windows) - FILE Privilege Abuse (Metasploit)
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pandora FMS 3.1 - Authentication Bypass / Arbitrary File Upload (Metasploit)
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OP5 5.3.5/5.4.0/5.4.2/5.5.0/5.5.1 - 'welcome' Remote Command Execution (Metasploit)
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ASUSWRT 3.0.0.4.376_1071 - LAN Backdoor Command Execution
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
e107 2 Bootstrap CMS - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 8.1 (x86/x64) - 'ahcache.sys' NtApphelpCacheControl Privilege Escalation
The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1,
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProjectSend - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Social Microblogging PRO 1.5 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Notepad++ 6.6.9 - Buffer Overflow
Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Ev
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GIT 1.8.5.6/1.9.5/2.0.5/2.1.4/2.2.1 & Mercurial < 3.2.3 - Multiple Vulnerabilities (Metasploit)
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbi
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GIT 1.8.5.6/1.9.5/2.0.5/2.1.4/2.2.1 & Mercurial < 3.2.3 - Multiple Vulnerabilities (Metasploit)
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderb
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Malwarebytes Anti-Malware < 2.0.3 / Anti-Exploit < 1.03.1.1220 - Update Code Execution (Metasploit)
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tuleap - PHP Unserialize Code Execution (Metasploit)
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenEMR 4.1.2(7) - Multiple SQL Injections
Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kerberos - Privilege Escalation (MS14-068)
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tincd - (Authenticated) Remote TCP Stack Buffer Overflow (Metasploit)
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pr
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX - IOKit Keyboard Driver Privilege Escalation (Metasploit)
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin DB Backup - Arbitrary File Download
Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote at
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advantech EKI-6340 - Command Injection
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrar
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hikvision DVR - RTSP Request Remote Code Execution (Metasploit)
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin SP Client Document Manager 2.4.1 - SQL Injection
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution / PowerShell VirtualAlloc (MS14-064)
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.