Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.064 exploits
Exploit-DB
Simple E-document 1.31 - Authentication Bypass
SQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB
iTechClassifieds 3.03.057 - SQL Injection
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoToMeeting for Android - Multiple Local Information Disclosure Vulnerabilities
The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which a
23RIESGO
abrir ↗Metasploit600
Simple E-Document Arbitrary File Upload
Simple E-Document Arbitrary File Upload RCE
63RIESGO
abrir ↗Metasploit600
GE Proficy CIMPLICITY gefebt.exe Remote Code Execution
GE Proficy HMI/SCADA Path Traversal
78RIESGO
abrir ↗Metasploit0
Firefox Proxy Prototype Privileged Javascript Injection
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RIESGO
abrir ↗Metasploit0
Firefox Proxy Prototype Privileged Javascript Injection
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MuPDF 1.3 - 'xps_parse_color()' Stack Buffer Overflow
Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote a
28RIESGO
abrir ↗Exploit-DB
Teracom Modem T2-B-Gawv1.4U10Y-BI - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem
23RIESGO
abrir ↗Exploit-DB
ASUS RT-N56U - Remote Buffer Overflow (ROP)
Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow
23RIESGO
abrir ↗Metasploit300
Mac OS X Safari file:// Redirection Sandbox Escape
The history implementation in WebKit, as used in Apple Safari before 6.2.6, 7.x before 7.1.6, and 8.x before 8.0.6, allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Sexy polling 1.0.8 - 'answer_id' SQL Injection
SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! a
23RIESGO
abrir ↗Metasploit500
Oracle Forms and Reports Remote Code Execution
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
100RIESGO
abrir ↗Metasploit500
Oracle Forms and Reports Remote Code Execution
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and
60RIESGO
abrir ↗Exploit-DB
Collabtive 1.1 - 'managetimetracker.php' SQL Injection
SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execu
23RIESGO
abrir ↗Exploit-DB
PHPJabbers Appointment Scheduler 2.0 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attacker
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Atmail Webmail Server - Email Body HTML Injection
Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Supply Chain Products Suite - Remote Security
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.
50RIESGO
abrir ↗Exploit-DB
Conceptronic Wireless Pan & Tilt Network Camera - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21
28RIESGO
abrir ↗Exploit-DB
Burden 1.8 - Authentication Bypass
The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and
28RIESGO
abrir ↗Exploit-DB
SoapUI 4.6.3 - Remote Code Execution
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts2 2.0.0 < 2.3.15 - Prefixed Parameters OGNL Injection
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SerComm Device - Remote Code Execution (Metasploit)
The Cisco WAP4410N access point with firmware through 2.0.6.1, WRVS4400N router with firmware 1.x through 1.1.13 and 2.x
60RIESGO
abrir ↗Metasploit400
KingScada kxClientDownload.ocx ActiveX Remote Code Execution
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before
50RIESGO
abrir ↗Exploit-DB
Horizon QCMS 4.0 - Multiple Vulnerabilities
SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows rem
23RIESGO
abrir ↗Exploit-DB
PHPJabbers Event Booking Calendar 2.0 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attacke
23RIESGO
abrir ↗Exploit-DB
PHPJabbers Appointment Scheduler 2.0 - Multiple Vulnerabilities
Directory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary file
23RIESGO
abrir ↗Exploit-DB
PHPJabbers Event Booking Calendar 2.0 - Multiple Vulnerabilities
SQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to exe
23RIESGO
abrir ↗Exploit-DB
Linux Kernel (Ubuntu 11.10/12.04) - binfmt_script Stack Data Disclosure
The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, whic
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dell Kace 1000 Systems Management Appliance DS-2014-001 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remot
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.