Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
Exploit-DB✓ VexDay Proof
Skia - Heap Overflow in SkScan::FillPath due to Precision Error
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RIESGO
abrir ↗Exploit-DB
Online Trade 1 - Information Disclosure
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SoftNAS Cloud < 4.0.3 - OS Command Injection
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RIESGO
abrir ↗Exploit-DB
Trivum Multiroom Setup Tool 8.76 - Corss-Site Request Forgery (Admin Bypass)
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, all
28RIESGO
abrir ↗Metasploit600
Network Manager VPNC Username Privilege Escalation
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac
56RIESGO
abrir ↗Exploit-DB
GetGo Download Manager 6.2.1.3200 - Denial of Service (PoC)
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RIESGO
abrir ↗GitHub PoC
PercussiveElbow/CVE-2004-2271-MiniShare-1.4.1-Buffer-Overflow
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RIESGO
abrir ↗Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RIESGO
abrir ↗Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RIESGO
abrir ↗Exploit-DB
Nagios Core 4.4.1 - Denial of Service
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RIESGO
abrir ↗Exploit-DB
Nagios Core 4.4.1 - Denial of Service
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows atta
23RIESGO
abrir ↗Exploit-DB
Nagios Core 4.4.1 - Denial of Service
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RIESGO
abrir ↗GitHub PoC★ 8
CVE-2013-6117
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RIESGO
abrir ↗Exploit-DB
Davolink DVW 3200 Router - Password Disclosure
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke
28RIESGO
abrir ↗Exploit-DB
Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allo
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RIESGO
abrir ↗Exploit-DB
Inteno’s IOPSYS - (Authenticated) Local Privilege Escalation
read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /v
23RIESGO
abrir ↗GitHub PoC★ 2
This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and En
60RIESGO
abrir ↗Exploit-DB
Touchpad / Trivum WebTouch Setup 2.53 build 13163 - Authentication Bypass
Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attacker
35RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Su
50RIESGO
abrir ↗Exploit-DB
MSVOD 10 - 'cid' SQL Injection
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
23RIESGO
abrir ↗Exploit-DB
TP-Link TL-WR840N - Denial of Service
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Su
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux - BPF Sign Extension Local Privilege Escalation (Metasploit)
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin All In One Favicon 4.6 - (Authenticated) Cross-Site Scripting
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.