Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.776GitHub PoC 15.367VulnCheck XDB 9019Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.557 exploits
Exploit-DB
DeDeCMS < 5.7-sp1 - Remote File Inclusion
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
35RIESGO
abrir ↗Metasploit600
Watchguard XCS Remote Command Execution
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell
50RIESGO
abrir ↗Exploit-DB
XOOPS < 2.0.11 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitra
23RIESGO
abrir ↗Metasploit600
Endian Firewall Proxy Password Change Command Injection
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir ↗Metasploit400
Pallete Projects Werkzeug Debugger Remote Code Execution
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
36RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Havij - OLE Automation Array Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Exploit-DB
ManageEngine Asset Explorer 6.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attacker
23RIESGO
abrir ↗GitHub PoC★ 6
A script, in C, to check if CGI scripts are vulnerable to CVE-2014-6271 (The Bash Bug).
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RIESGO
abrir ↗Exploit-DB
Koha 3.20.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and
23RIESGO
abrir ↗Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x
23RIESGO
abrir ↗Exploit-DB
Koha 3.20.1 - Directory Traversal
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08
50RIESGO
abrir ↗Exploit-DB
Thycotic Secret Server 8.8.000004 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before
23RIESGO
abrir ↗Exploit-DB
GeniXCMS 0.0.3 - 'register.php' SQL Injection
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - ClientCopyImage Win32k (MS15-051) (Metasploit)
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - ShaderJob Buffer Overflow (Metasploit)
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RIESGO
abrir ↗Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject ar
23RIESGO
abrir ↗Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vesta Control Panel 0.9.8 - OS Command Injection
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code
28RIESGO
abrir ↗Metasploit500
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows an
100RIESGO
abrir ↗Metasploit500
Adobe Flash Player Nellymoser Audio Decoding Buffer Overflow
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.gif' Parsing Memory Corruption
Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to ex
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS < 2.0.3 - Multiple Vulnerabilities
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tango DropBox 3.1.5 + PRO - Activex HeapSpray
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSell
23RIESGO
abrir ↗Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to writ
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lively Cart - SQL Injection
SQL injection vulnerability in LivelyCart 1.2.0 allows remote attackers to execute arbitrary SQL commands via the search
23RIESGO
abrir ↗Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authentica
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.