Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.063exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.520VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.063 exploits
Exploit-DB✓ VexDay Proof
PHPFox - Access Control Security Bypass
static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restric
23RIESGO
abrir ↗Exploit-DB
A10 Networks ACOS 2.7.0-P2 (Build 53) - Buffer Overflow (PoC)
Buffer overflow in A10 Networks Advanced Core Operating System (ACOS) before 2.7.0-p6 and 2.7.1 before 2.7.1-P1_55 allow
28RIESGO
abrir ↗Metasploit600
eScan Web Management Console Command Injection
eScan 5.5-2 Web Management Console Command Injection
63RIESGO
abrir ↗Metasploit600
Belkin Wemo UPnP Remote Code Execution
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetS
40RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ibstat $PATH - Local Privilege Escalation (Metasploit)
Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, a
38RIESGO
abrir ↗Exploit-DB
WordPress Plugin XCloner 3.1.0 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers
23RIESGO
abrir ↗Exploit-DB
Oracle Identity Manager 11g R2 SP1 (11.1.2.1.0) - Unvalidated Redirects
Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.
23RIESGO
abrir ↗Exploit-DB
CIS Manager CMS - SQL Injection
SQL injection vulnerability in default.asp in CIS Manager CMS allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Metasploit300
MS14-017 Microsoft Word RTF Object Confusion
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi
100RIESGO
abrir ↗Exploit-DB
PhonerLite 2.14 SIP Soft Phone - SIP Digest Disclosure
The PhonerLite phone before 2.15 provides hashed credentials in a response to an invalid authentication challenge, which
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Ajax Pagination 1.1 - Local File Inclusion
Directory traversal vulnerability in the Ajax Pagination (twitter Style) plugin 1.1 for WordPress allows remote attacker
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SePortal 2.5 - SQL Injection / Remote Code Execution (Metasploit)
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RIESGO
abrir ↗Exploit-DB
EMC Cloud Tiering Appliance 10.0 - XML External Entity Arbitrary File Read (Metasploit)
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login reques
50RIESGO
abrir ↗Metasploit300
EMC CTA v10.0 Unauthenticated XXE Arbitrary File Read
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login reques
50RIESGO
abrir ↗Metasploit300
AlienVault Authenticated SQL Injection Arbitrary File Read
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier
43RIESGO
abrir ↗GitHub PoC★ 3
Attempts to exploit CVE-2012-3137 on vulnerable Oracle servers
The authentication protocol in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 all
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fitnesse Wiki - Remote Command Execution (Metasploit)
FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAN
23RIESGO
abrir ↗Exploit-DB
Dell SonicWALL EMail Security Appliance Application 7.4.5 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Dell SonicWALL Email Security 7.4.5 and earlier allow remote auth
23RIESGO
abrir ↗Exploit-DB
IBM Tealeaf CX 8.8 - Remote OS Command Injection
delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2
28RIESGO
abrir ↗Exploit-DB
IBM Tealeaf CX 8.8 - Remote OS Command Injection
Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Katello (RedHat Satellite) - users/update_roles Missing Authorisation (Metasploit)
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update
50RIESGO
abrir ↗Exploit-DB
Allied Telesis AT-RG634A ADSL Broadband Router - Web Shell
The administrative interface in Allied Telesis AT-RG634A ADSL Broadband router 3.3+, iMG624A firmware 3.5, iMG616LH firm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache CouchDB 1.5.0 - 'uuids' Denial of Service
Apache CouchDB 1.5.0 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via t
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
InterWorx Control Panel 5.0.13 build 574 - 'xhr.php?i' SQL Injection
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreePBX - 'config.php' Remote Code Execution (Metasploit)
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Light Audio Player 1.0.14 - Memory Corruption (PoC)
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BigDump 0.35b - Arbitrary File Upload
Unrestricted file upload vulnerability in bigdump.php in Alexey Ozerov BigDump 0.29b allows remote attackers to execute
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symphony 2.2.4 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
jetVideo 8.1.1 - Basic '.wav' Local Crash (PoC)
Microsoft Windows Media Player (WMP) 11.0.5721.5230 allows remote attackers to cause a denial of service (memory corrupt
35RIESGO
abrir ↗Metasploit300
Katello (Red Hat Satellite) users/update_roles Missing Authorization
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.