Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.064 exploits
Exploit-DB
GDL 4.2 - Multiple Vulnerabilities
Multiple directory traversal vulnerabilities in class/session.php in Ganesha Digital Library (GDL) 4.2 allow remote atta
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager - Remote Command Execution (Metasploit)
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager - Remote Command Execution (Metasploit)
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RIESGO
abrir ↗Exploit-DB
Piwigo 2.6.1 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
POSH 3.1.x - 'addtoapplication.php' SQL Injection
SQL injection vulnerability in portal/addtoapplication.php in POSH (aka Posh portal or Portaneo) 3.0 before 3.3.0 allows
23RIESGO
abrir ↗Metasploit300
JIRA Issues Collector Directory Traversal
Directory traversal vulnerability in the Issue Collector plugin in Atlassian JIRA before 6.0.4 allows remote attackers t
43RIESGO
abrir ↗Exploit-DB
Technicolor TC7200 - Credentials Disclosure
Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sendy 1.1.8.4 - SQL Injection
SQL injection vulnerability in /app in Sendy 1.1.8.4 allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir ↗Exploit-DB
Python - 'socket.recvfrom_into()' Remote Buffer Overflow
Buffer overflow in the socket.recvfrom_into function in Modules/socketmodule.c in Python 2.5 before 2.7.7, 3.x before 3.
28RIESGO
abrir ↗Metasploit600
Symantec Endpoint Protection Manager /servlet/ConsoleServlet Remote Command Execution
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RIESGO
abrir ↗Metasploit600
Symantec Endpoint Protection Manager /servlet/ConsoleServlet Remote Command Execution
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 11.0/12.0/12.1 - Remote Command Execution
SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.74
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 11.0/12.0/12.1 - Remote Command Execution
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin AdRotate 3.9.4 - 'clicktracker.ph?track' SQL Injection
SQL injection vulnerability in library/clicktracker.php in the AdRotate Pro plugin 3.9 through 3.9.5 and AdRotate Free p
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ultra Mini HTTPd 1.21 - 'POST' Remote Stack Buffer Overflow (2)
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RIESGO
abrir ↗Exploit-DB
ILIAS 4.4.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inje
23RIESGO
abrir ↗Metasploit400
SolidWorks Workgroup PDM 2014 pdmwService.exe Arbitrary File Write
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RIESGO
abrir ↗Exploit-DB
ILIAS 4.4.1 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrar
23RIESGO
abrir ↗Exploit-DB
ILIAS 4.4.1 - Multiple Vulnerabilities
ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SolidWorks Workgroup PDM 2014 SP2 - Arbitrary File Write
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ATutor - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote auth
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eshtery CMS - 'FileManager.aspx' Local File Disclosure
Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname
28RIESGO
abrir ↗Exploit-DB
Stark CRM 1.0 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Stark CRM 1.0 allow remote attackers to hijack the authent
23RIESGO
abrir ↗Exploit-DB
Stark CRM 1.0 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PCMan FTP Server 2.07 - Remote Buffer Overflow
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MediaWiki - 'Thumb.php' Remote Command Execution (Metasploit)
MediaWiki 1.22.x before 1.22.2, 1.21.x before 1.21.5, and 1.19.x before 1.19.11, when DjVu or PDF file upload support is
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dassault Systemes Catia - Remote Stack Buffer Overflow
Dassault Systemes Catia V5-6R2013: Stack Buffer Overflow due to inadequate boundary checks
23RIESGO
abrir ↗Metasploit300
Linksys WRT120N tmUnblock Stack Buffer Overflow
Linksys WRT120N tmUnblock.cgi Stack-Based Buffer Overflow Admin Password Reset
28RIESGO
abrir ↗Exploit-DB
SolidWorks Workgroup PDM 2014 SP2 Opcode 2001 - Denial of Service
Multiple stack-based buffer overflows in pdmwService.exe in SolidWorks Workgroup PDM 2014 SP2 allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ultra Mini HTTPd 1.21 - 'POST' Remote Stack Buffer Overflow (1)
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.