Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
22.786 exploits
Exploit-DB
WordPress Plugin WPAMS - SQL Injection
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir ↗Exploit-DB
TicketPlus - Arbitrary File Upload
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
23RIESGO
abrir ↗Exploit-DB
Job Links - Arbitrary File Upload
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin School Management System - SQL Injection
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin WPCHURCH - SQL Injection
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Hospital Management System - SQL Injection
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir ↗Exploit-DB
SMSmaster - SQL Injection
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir ↗Exploit-DB
AMC Master - Arbitrary File Upload
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handli
23RIESGO
abrir ↗Exploit-DB
Photo Fusion - Arbitrary File Upload
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
23RIESGO
abrir ↗Exploit-DB
Apple iOS 10.2 - Broadcom Out-of-Bounds Write when Handling 802.11k Neighbor Report Response
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RIESGO
abrir ↗Exploit-DB
Supervisor 3.0a1 < 3.3.2 - XML-RPC (Authenticated) Remote Code Execution (Metasploit)
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir ↗Exploit-DB
Adobe Flash - Out-of-Bounds Write in MP4 Edge Processing
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RIESGO
abrir ↗Exploit-DB
Adobe Flash - Out-of-Bounds Memory Read in MP4 Parsing
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RIESGO
abrir ↗Exploit-DB
Oracle 9i XDB 9.2.0.1 - HTTP PASS Buffer Overflow
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RIESGO
abrir ↗Exploit-DB
Adobe Flash - Out-of-Bounds Read in applyToRange
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation co
35RIESGO
abrir ↗Exploit-DB
CyberLink LabelPrint < 2.5 - Local Buffer Overflow (SEH Unicode)
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RIESGO
abrir ↗Exploit-DB
Claydip Airbnb Clone 1.0 - Arbitrary File Upload
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Larav
23RIESGO
abrir ↗Exploit-DB
Cash Back Comparison Script 1.0 - SQL Injection
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Exploit-DB
Linux Kernel < 4.13.1 - BlueTooth Buffer Overflow (PoC)
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RIESGO
abrir ↗Exploit-DB
PHPMyFAQ 2.9.8 - Cross-Site Scripting (1)
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject
23RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra - 'JavascriptFunction::ReparseAsmJsModule' Incorrectly Re-parses
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
45RIESGO
abrir ↗Exploit-DB
ERS Data System 1.8.1 - Java Deserialization
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.Upd
23RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra - 'Parser::ParseCatch' Does Not Handle 'eval()' (Denial of Service)
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RIESGO
abrir ↗Exploit-DB
Microsoft Edge - Chakra Incorrectly Parses Object Patterns
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RIESGO
abrir ↗Exploit-DB
Android Bluetooth - 'Blueborne' Information Leak (2)
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir ↗Exploit-DB
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗Exploit-DB
Microsoft Edge 38.14393.1066.0 - Memory Corruption with Partial Page Loading
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the
35RIESGO
abrir ↗Exploit-DB
Microsoft Edge 38.14393.1066.0 - 'COptionsCollectionCacheItem::GetAt' Out-of-Bounds Read
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arb
35RIESGO
abrir ↗Exploit-DB
HPE < 7.2 - Java Deserialization
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01,
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.