Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.003exploits catalogados
37.620CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.011GitHub PoC 15.501VulnCheck XDB 9077Nuclei 4427Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.003 exploits
Exploit-DB✓ VexDay Proof
Xangati - '/servlet/MGConfigData' Multiple Directory Traversals
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Twitget 3.3.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xangati - '/servlet/Installer?file' Directory Traversal
Multiple directory traversal vulnerabilities in Xangati XSR before 11 and XNR before 7 allow remote attackers to read ar
23RIESGO
abrir ↗GitHub PoC
Test script for test 1Password database for SSL Hea(r)t Bleeding (CVE-2014-0160)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB
CubeCart 5.2.8 - Session Fixation
Session fixation vulnerability in CubeCart before 5.2.9 allows remote attackers to hijack web sessions via the PHPSESSID
23RIESGO
abrir ↗Metasploit400
Adobe Reader for Android addJavascriptInterface Exploit
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows r
60RIESGO
abrir ↗VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC★ 1
A research tool designed to check for OpenSSL CVE-2014-0160 vulnerability
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
Nmap NSE script that discovers/exploits Heartbleed/CVE-2014-0160.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC★ 5
POC for CVE-2014-0160 (Heartbleed) for DTLS
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC★ 6
Script to find Exit and Guard nodes in the Tor Network, that are still suffering from CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB
Sendy 1.1.9.1 - SQL Injection
SQL injection vulnerability in /send-to in Sendy 1.1.9.1 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗GitHub PoC★ 2
OpenSSL Heartbleed (CVE-2014-0160) vulnerability scanner.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
CVE-2014-0160 scanner
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB
XCloner Standalone 3.5 - Cross-Site Request Forgery
XCloner Standalone 3.5 and earlier, when enable_db_backup and sql_mem are enabled, allows remote authenticated administr
23RIESGO
abrir ↗GitHub PoC★ 2
This repo contains a script to automatically test sites for vulnerability to the Heartbleed Bug (CVE-2014-0160) based on the input file for the urls.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
20RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Word - RTF Object Confusion (MS14-017) (Metasploit)
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vtiger - 'Install' Remote Command Execution (Metasploit)
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all
50RIESGO
abrir ↗GitHub PoC★ 8
Heartbleed variants
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
CVE-2014-0160 mass test against subdomains
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
ice-security88/CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC★ 1
OpenSSL Heartbleed (CVE-2014-0160) Fix script
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sophos Web Protection Appliance Interface - (Authenticated) Arbitrary Command Execution (Metasploit)
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RIESGO
abrir ↗VulnCheck XDB
infoleak
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB
Orbit Open Ad Server 1.1.0 - SQL Injection
SQL injection vulnerability in OrbitScripts Orbit Open Ad Server before 1.1.1 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.