Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
VulnCheck XDB
infoleak
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir ↗GitHub PoC★ 205
Script to test for Cisco ASA path traversal vulnerability (CVE-2018-0296) and extract system information.
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir ↗GitHub PoC★ 107
Test CVE-2018-0296 and extract usernames
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (1)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir ↗Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add User)
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
23RIESGO
abrir ↗Exploit-DB
Dell EMC RecoverPoint < 5.1.2 - Local Root Command Execution
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje
35RIESGO
abrir ↗Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add Admin)
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen
23RIESGO
abrir ↗GitHub PoC
Ektron Content Management System (CMS) 9.20 SP2, remote re-enabling users (CVE-2018–12596)
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at
28RIESGO
abrir ↗Exploit-DB
Redis 5.0 - Denial of Service
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers t
28RIESGO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro
23RIESGO
abrir ↗GitHub PoC★ 1
CVE-2017-5792
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - Desktop Bridge Activation Arbitrary Directory Creation Privilege Escalation
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - Desktop Bridge Virtual Registry CVE-2018-0880 Incomplete Fix Privilege Escalation
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RIESGO
abrir ↗Exploit-DB
IPConfigure Orchid VMS 2.0.5 - Directory Traversal / Information Disclosure (Metasploit)
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache CouchDB < 2.1.0 - Remote Code Execution
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RIESGO
abrir ↗GitHub PoC★ 9
MS15-034 HTTP.sys 远程执行代码检测脚本(MS15-034 HTTP.sys remote execution code poc script)
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi
23RIESGO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi
23RIESGO
abrir ↗Exploit-DB
ntp 4.2.8p11 - Local Buffer Overflow (PoC)
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or es
28RIESGO
abrir ↗VulnCheck XDB
denial-of-service
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗Exploit-DB
MaDDash 2.0.2 - Directory Listing
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
23RIESGO
abrir ↗GitHub PoC
malindarathnayake/Intel-CVE-2018-3639-Mitigation_RegistryUpdate
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RIESGO
abrir ↗GitHub PoC★ 1
CVE-2016-2098 simple POC written in bash
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir ↗Metasploit400
phpMyAdmin Authenticated Remote Code Execution
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir ↗Metasploit600
MicroFocus Secure Messaging Gateway Remote Code Execution
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RIESGO
abrir ↗Metasploit600
MicroFocus Secure Messaging Gateway Remote Code Execution
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RIESGO
abrir ↗Metasploit600
Axis Network Camera .srv-to-parhand RCE
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RIESGO
abrir ↗Metasploit600
Axis Network Camera .srv-to-parhand RCE
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RIESGO
abrir ↗Metasploit600
Axis Network Camera .srv-to-parhand RCE
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RIESGO
abrir ↗Exploit-DB
Nikto 2.1.6 - CSV Injection
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.