Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.805exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.428VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.805 exploits
Exploit-DB
CS-Cart 4.2.4 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in CS-Cart 4.2.4 allows remote attackers to hijack the authentication of
23RIESGO
abrir ↗Exploit-DB
Foxit Products GIF Conversion - 'LZWMinimumCodeSize' Memory Corruption
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ElasticSearch - Remote Code Execution
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir ↗Exploit-DB
Foxit Products GIF Conversion - 'DataSubBlock' Memory Corruption
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Text Services Memory Corruption (MS15-020)
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
28RIESGO
abrir ↗Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack th
23RIESGO
abrir ↗Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Exploit-DB
GeniXCMS 0.0.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB
CodoForum 2.5.1 - Arbitrary File Download
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RIESGO
abrir ↗Metasploit600
Microsoft Windows Shell LNK Code Execution
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
60RIESGO
abrir ↗Metasploit600
Microsoft Windows Shell LNK Code Execution
Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
60RIESGO
abrir ↗Metasploit600
WordPress WPshop eCommerce Arbitrary File Upload Vulnerability
WPshop 2 – E-Commerce < 1.3.9.6 - Arbitrary File Upload
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rowhammer - NaCl Sandbox Escape
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates fo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel (x86-64) - Rowhammer Privilege Escalation
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rowhammer - NaCl Sandbox Escape
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RIESGO
abrir ↗GitHub PoC★ 85
:broken_heart: Hearbleed exploit to retrieve sensitive information CVE-2014-0160 :broken_heart:
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB
Elastix 2.x - Blind SQL Injection
SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and earlier allows remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector 8.10 - Remote Command Execution (Metasploit)
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RIESGO
abrir ↗Exploit-DB
PHP Betoffice (Betster) 1.0.4 - Authentication Bypass / SQL Injection
Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB
ProjectSend r561 - SQL Injection
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to
23RIESGO
abrir ↗Exploit-DB
Linux Kernel 3.17.5 - IRET Instruction #SS Fault Handling Crash (PoC)
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RIESGO
abrir ↗Exploit-DB
Linux Kernel 3.15.6 - PPP-over-L2TP Socket Level Handling Crash (PoC)
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Web Gateway 5 - 'restore.php' (Authenticated) Command Injection (Metasploit)
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RIESGO
abrir ↗Exploit-DB
SolarWinds Orion Service - SQL Injection
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RIESGO
abrir ↗Exploit-DB
Linux Kernel 3.16.3 - Associative Array Garbage Collection Crash (PoC)
The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RIESGO
abrir ↗Metasploit300
WordPress CP Multi-View Calendar Unauthenticated SQL Injection Scanner
SQL injection vulnerability in the CP Multi View Event Calendar plugin 1.01 for WordPress allows remote attackers to exe
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.