Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.753exploits catalogados
37.445CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.871GitHub PoC 15.407VulnCheck XDB 9065Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.753 exploits
Exploit-DB
HP WebInspect 10.4 - XML External Entity Injection
Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote authenticated users to by
23RIESGO
abrir ↗Exploit-DB
ISPConfig 3.0.5.4p6 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijac
23RIESGO
abrir ↗Exploit-DB
Libmimedir - '.VCF' Memory Corruption (PoC)
libmimedir allows remote attackers to execute arbitrary code via a VCF file with two NULL bytes at the end of the file,
28RIESGO
abrir ↗Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir ↗Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Paypal Currency Converter Basic For WooCommerce - File Read
Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic
28RIESGO
abrir ↗Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
SysAid Help Desk before 15.2 uses a hardcoded password of Password1 for the sa SQL Server Express user account, which al
23RIESGO
abrir ↗Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary
23RIESGO
abrir ↗Exploit-DB
ISPConfig 3.0.5.4p6 - Multiple Vulnerabilities
SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated user
23RIESGO
abrir ↗Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir ↗Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
SysAid Help Desk before 15.2 allows remote attackers to cause a denial of service (CPU and memory consumption) via a lar
23RIESGO
abrir ↗Exploit-DB
SysAid Help Desk 14.4 - Multiple Vulnerabilities
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers t
50RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
redhatkaty/-cve-2010-3904-report
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir ↗VulnCheck XDB
local
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir ↗GitHub PoC
marstornado/cve-2014-0160-Yunfeng-Jiang
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Milw0rm Clone Script 1.0 - 'related.php?program' Blind SQL Injection
SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗GitHub PoC★ 2
weidongl74/cve-2015-2315-report
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject
23RIESGO
abrir ↗GitHub PoC
system reading course
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Nmedia WordPress Member Conversation 1.35.0 - 'doupload.php' Arbitrary File Upload
Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion
Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin zM Ajax Login & Register 1.0.9 - Local File Inclusion
Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attack
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SysAid Help Desk Administrator Portal < 14.4 - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RIESGO
abrir ↗Metasploit300
SysAid Help Desk Database Credentials Disclosure
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir ↗Metasploit300
SysAid Help Desk Arbitrary File Download
Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrar
60RIESGO
abrir ↗Metasploit300
SysAid Help Desk Database Credentials Disclosure
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir ↗Metasploit600
SysAid Help Desk 'rdslogs' Arbitrary File Upload
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir ↗Metasploit600
SysAid Help Desk Administrator Portal Arbitrary File Upload
Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators t
50RIESGO
abrir ↗Metasploit300
SysAid Help Desk Arbitrary File Download
SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the account
50RIESGO
abrir ↗Metasploit300
SysAid Help Desk Administrator Account Creation
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers t
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.