Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.776GitHub PoC 15.367VulnCheck XDB 9019Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.557 exploits
Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in
28RIESGO
abrir ↗Exploit-DB
ZenPhoto 1.4.8 - Multiple Vulnerabilities
SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - opaqueBackground Use-After-Free (Metasploit)
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RIESGO
abrir ↗Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and
23RIESGO
abrir ↗Exploit-DB
ZenPhoto 1.4.8 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack
23RIESGO
abrir ↗Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
Multiple Cross-Site Scripting (XSS) vulnerabilities exist in Simple Online Planning (SOPlanning) before 1.33 via the doc
23RIESGO
abrir ↗Exploit-DB
ArticleFR 3.0.6 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Accellion FTA - getStatus verify_oauth_token Command Execution (Metasploit)
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach
60RIESGO
abrir ↗Exploit-DB
ArticleFR 3.0.6 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to injec
23RIESGO
abrir ↗Exploit-DB
Arab Portal 3 - SQL Injection
SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail
23RIESGO
abrir ↗Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which all
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Western Digital Arkeia < 11.0.12 - Remote Code Execution (Metasploit)
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to b
60RIESGO
abrir ↗Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke
50RIESGO
abrir ↗Exploit-DB
FreiChat 9.6 - SQL Injection
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows
23RIESGO
abrir ↗Exploit-DB
ZenPhoto 1.4.8 - Multiple Vulnerabilities
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Swim Team 1.44.10777 - Arbitrary File Download
Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allo
50RIESGO
abrir ↗GitHub PoC★ 15
Vulnerability as a service: showcasing CVS-2014-0160, a.k.a. Heartbleed
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC★ 22
Vulnerability as a service: showcasing CVS-2014-6271, a.k.a. Shellshock
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Metasploit0
ManageEngine EventLog Analyzer Remote Code Execution
ZOHO ManageEngine EventLog Analyzer 10.6 build 10060 and earlier allows remote attackers to bypass intended restrictions
60RIESGO
abrir ↗Metasploit0
MS15-078 Microsoft Windows Font Driver Buffer Overflow
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RIESGO
abrir ↗Metasploit0
MS15-078 Microsoft Windows Font Driver Buffer Overflow
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
43RIESGO
abrir ↗Metasploit600
X11 Keyboard Command Injection
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
23RIESGO
abrir ↗Metasploit600
Accellion FTA getStatus verify_oauth_token Command Execution
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach
60RIESGO
abrir ↗Metasploit500
Western Digital Arkeia Remote Code Execution
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to b
60RIESGO
abrir ↗Metasploit300
Accellion FTA 'statecode' Cookie Arbitrary File Read
Directory traversal vulnerability in the template function in function.inc in Accellion File Transfer Appliance devices
30RIESGO
abrir ↗Metasploit300
OpenSSL Alternative Chains Certificate Forgery MITM Proxy
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RIESGO
abrir ↗Exploit-DB
Centreon 2.5.4 - Multiple Vulnerabilities
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centre
23RIESGO
abrir ↗Exploit-DB
Orchard CMS 1.7.3/1.8.2/1.9.0 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AirLive (Multiple Products) - OS Command Injection
cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.