Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.064 exploits
Exploit-DB
SpagoBI 4.0 - Persistent HTML Script Insertion
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ALLPlayer 5.8.1 - '.m3u' Local Buffer Overflow (SEH)
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrat
23RIESGO
abrir ↗Exploit-DB
SpagoBI 4.0 - Arbitrary Cross-Site Scripting / Arbitrary File Upload
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execut
23RIESGO
abrir ↗Exploit-DB
SpagoBI 4.0 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RIESGO
abrir ↗Metasploit300
Joomla weblinks-categories Unauthenticated SQL Injection Arbitrary File Read
SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL
18RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Demantra 12.2.1 - Database Credentials Disclosure
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Demantra 12.2.1 - Arbitrary File Disclosure
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Demantra 12.2.1 - SQL Injection
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Demantra 12.2.1 - Persistent Cross-Site Scripting
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RIESGO
abrir ↗Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharact
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5
23RIESGO
abrir ↗Exploit-DB
SpagoBI 4.0 - Privilege Escalation
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Li
23RIESGO
abrir ↗Exploit-DB
Plex Media Server 0.9.9.2.374-aa23a69 - Multiple Vulnerabilities
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and e
23RIESGO
abrir ↗Exploit-DB
Plex Media Server 0.9.9.2.374-aa23a69 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrar
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for Wor
28RIESGO
abrir ↗Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attem
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin befo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VCDGear 3.50 - '.cue' Local Stack Buffer Overflow
Multiple stack-based buffer overflows in VCDGear 3.55 allow user-assisted remote attackers to execute arbitrary code via
23RIESGO
abrir ↗Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo befor
23RIESGO
abrir ↗Metasploit300
Oracle Demantra Arbitrary File Retrieval with Authentication Bypass
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir ↗Metasploit300
Oracle Demantra Arbitrary File Retrieval with Authentication Bypass
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GE Proficy CIMPLICITY - 'gefebt.exe' Remote Code Execution (Metasploit)
GE Proficy HMI/SCADA Path Traversal
78RIESGO
abrir ↗Metasploit300
MantisBT Admin SQL Injection Arbitrary File Read
SQL injection vulnerability in the manage configuration page (adm_config_report.php) in MantisBT 1.2.13 through 1.2.16 a
23RIESGO
abrir ↗Metasploit300
Oracle Demantra Database Credentials Leak
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir ↗Metasploit300
Oracle Demantra Database Credentials Leak
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir ↗Exploit-DB
GDL 4.2 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote atta
23RIESGO
abrir ↗Exploit-DB
GDL 4.2 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in module/search/function.php in Ganesha Digital Library (GDL) 4.2 allows remot
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.