Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.842exploits catalogados
37.493CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 23.901GitHub PoC 15.465VulnCheck XDB 9066Nuclei 4426Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.842 exploits
Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB
Clipbucket 2.7 RC3 0.9 - Blind SQL Injection
SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execut
23RIESGO
abrir ↗Metasploit500
D-Link DCS-931L File Upload
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use
50RIESGO
abrir ↗Exploit-DB
Beehive Forum 1.4.4 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to i
23RIESGO
abrir ↗Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attac
23RIESGO
abrir ↗Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbi
23RIESGO
abrir ↗Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authe
23RIESGO
abrir ↗GitHub PoC★ 3
This is a Python Application that helps you detect if your machine that run bash is vulnerable by CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB
Samsung iPOLiS 1.12.2 - iPOLiS XnsSdkDeviceIpInstaller ActiveX WriteConfigValue (PoC)
Buffer overflow in the XnsSdkDeviceIpInstaller.ocx ActiveX control in Samsung iPOLiS Device Manager 1.12.2 allows remote
23RIESGO
abrir ↗VulnCheck XDB
client-side
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass t
60RIESGO
abrir ↗Exploit-DB
Piwigo 2.7.3 - SQL Injection
SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Publish-It 3.6d - Local Buffer Overflow (SEH)
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin Duplicator 0.5.8 - Privilege Escalation
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Java JMX - Server Insecure Configuration Java Code Execution (Metasploit)
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not r
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Fancybox 3.0.2 - Persistent Cross-Site Scripting
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote atta
23RIESGO
abrir ↗Exploit-DB
eTouch SamePage 4.4.0.0.239 - Multiple Vulnerabilities
SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin WonderPlugin Audio Player 2.0 - Blind SQL Injection / Cross-Site Scripting
Multiple SQL injection vulnerabilities in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow (1) remote
23RIESGO
abrir ↗Exploit-DB
eTouch SamePage 4.4.0.0.239 - Multiple Vulnerabilities
Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows r
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin WonderPlugin Audio Player 2.0 - Blind SQL Injection / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the Wo
23RIESGO
abrir ↗Exploit-DB
PCMan FTP Server 2.0.7 - 'MKD' Remote Buffer Overflow
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Webdorado Spider Event Calendar 1.4.9 - SQL Injection
SQL injection vulnerability in Spider Event Calendar 1.4.9 for WordPress allows remote attackers to execute arbitrary SQ
43RIESGO
abrir ↗Metasploit300
D-Link Devices HNAP SOAPAction-Header Command Execution
The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute ar
100RIESGO
abrir ↗Exploit-DB
Exponent CMS 2.3.1 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Video Gallery 2.7.0 - SQL Injection
SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin Video Gallery 2.7.0 - SQL Injection
Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly
23RIESGO
abrir ↗Exploit-DB
SoftSphere DefenseWall FW/IPS 3.24 - Local Privilege Escalation
The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memo
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Survey and Poll 1.1 - Blind SQL Injection
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 fo
23RIESGO
abrir ↗Metasploit600
Maarch LetterBox Unrestricted File Upload
Unrestricted file upload vulnerability in file_to_index.php in Maarch LetterBox 2.8 and earlier and GEC/GED 1.4 and earl
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.