Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9001Nuclei 4401Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.324 exploits
Exploit-DB✓ VexDay Proof
FTPShell Client 6.53 - Remote Buffer Overflow
Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP serv
50RIESGO
abrir ↗Metasploit300
FTPShell client 6.70 (Enterprise edition) Stack Buffer Overflow
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RIESGO
abrir ↗Metasploit600
DC/OS Marathon UI Docker Exploit
DC/OS Marathon UI < 1.9.0 Unauthenticated RCE via Docker Mount Abuse
43RIESGO
abrir ↗Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-
28RIESGO
abrir ↗Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS so
28RIESGO
abrir ↗Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http:
28RIESGO
abrir ↗Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
Remote file upload vulnerability in Wordpress Plugin Mobile App Native 3.0.
23RIESGO
abrir ↗Exploit-DB
Multiple WordPress Plugins - Arbitrary File Upload
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulner
28RIESGO
abrir ↗Exploit-DB
EPSON TMNet WebConfig 1.00 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB
WordPress Core < 4.7.1 - Username Enumeration
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Conext ComBox 865-1058 - Denial of Service
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830
35RIESGO
abrir ↗VulnCheck XDB
local
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir ↗GitHub PoC★ 81
An exploit for CVE-2016-7255 on Windows 7/8/8.1/10(pre-anniversary) 64 bit
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). Th
43RIESGO
abrir ↗Exploit-DB
D-Link DSL-2730U Wireless N 150 - Cross-Site Request Forgery
Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or fi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Aruba AirWave 8.2.3 - XML External Entity Injection / Cross-Site Scripting
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a
23RIESGO
abrir ↗Exploit-DB
Cisco AnyConnect Secure Mobility Client 4.3.04027 - Local Privilege Escalation
A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sophos Web Appliance 4.3.1.1 - Session Fixation
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.
23RIESGO
abrir ↗Exploit-DB
Netgear DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 all
23RIESGO
abrir ↗Exploit-DB
Netgear DGN2200v1/v2/v3/v4 - Cross-Site Request Forgery
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RIESGO
abrir ↗Exploit-DB
Synchronet BBS 3.16c - Denial of Service
Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string
23RIESGO
abrir ↗Metasploit300
SysGauge 1.5.18 SMTP Validation Buffer Overflow
An issue was discovered in SysGauge 1.5.18. A buffer overflow vulnerability in SMTP connection verification leads to arb
23RIESGO
abrir ↗Exploit-DB
WePresent WiPG-1500 - Backdoor Account
The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password
23RIESGO
abrir ↗Metasploit600
Logsign Remote Command Injection
Logsign Unified SecOps Platform Missing Authentication Remote Code Execution Vulnerability
36RIESGO
abrir ↗Exploit-DB
Linux Kernel 4.4.0 (Ubuntu) - DCCP Double-Free (PoC)
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RIESGO
abrir ↗Exploit-DB
Linux Kernel 4.4.0 (Ubuntu) - DCCP Double-Free Privilege Escalation
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netgear DGN2200v1/v2/v3/v4 - 'dnslookup.cgi' Remote Command Execution
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RIESGO
abrir ↗Metasploit600
Netgear DGN2200 dnslookup.cgi Command Injection
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit 10.0.2 - 'FrameLoader::clear' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit 10.0.2 - 'Frame::setDocument' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.