Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8182Nuclei 4217Metasploit 3462✓ solo verificadosrecientespopularesriesgo
22.786 exploits
Exploit-DB
CubeCart < 3.0.12 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote
23RIESGO
abrir ↗Exploit-DB
Eye of Gnome 3.10.2 - GMarkup Out of Bounds Write
Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib befor
28RIESGO
abrir ↗Exploit-DB
WordPress Core 4.5.3 - Directory Traversal / Denial of Service
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPre
35RIESGO
abrir ↗Exploit-DB
Ocomon 2.0 - SQL Injection
SQL injection vulnerability in OcoMon 1.21, and possibly other versions, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir ↗Exploit-DB
WordPress Core 4.5.3 - Directory Traversal / Denial of Service
Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.
43RIESGO
abrir ↗Exploit-DB
Fortigate Firewalls - 'EGREGIOUSBLUNDER' Remote Code Execution
Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9
35RIESGO
abrir ↗Exploit-DB
Cisco ASA / PIX - 'EPICBANANA' Local Privilege Escalation
Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows loc
76RIESGO
abrir ↗Exploit-DB
Watchguard Firewalls - 'ESCALATEPLOWMAN' ifconfig Privilege Escalation
WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifco
23RIESGO
abrir ↗Exploit-DB
Linux Kernel - TCP Related Read Use-After-Free
The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certai
23RIESGO
abrir ↗Exploit-DB
Cisco ASA 8.x - 'EXTRABACON' Authentication Bypass
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RIESGO
abrir ↗Exploit-DB
X-Cart < 4.1.3 - Arbitrary Variable Overwrite
Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to o
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows - GDI+ ValidateBitmapInfo Invalid Pointer Arithmetic Out-of-Bounds Reads (MS16-097)
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007
35RIESGO
abrir ↗Exploit-DB
Microsoft Windows - GDI+ EMR_EXTTEXTOUTA / EMR_POLYTEXTOUTA Heap Buffer Overflow (MS16-097)
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007
35RIESGO
abrir ↗Exploit-DB
Microsoft Windows - GDI+ DecodeCompressedRLEBitmap Invalid Pointer Arithmetic Out-of-Bounds Write (MS16-097)
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
35RIESGO
abrir ↗Exploit-DB
Microsoft Word 2013/2016 - sprmSdyaTop Denial of Service (MS16-099)
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a craf
35RIESGO
abrir ↗Exploit-DB
WSO2 Carbon 4.4.5 - Denial of Service / Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RIESGO
abrir ↗Exploit-DB
WSO2 Carbon 4.4.5 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB
WSO2 Carbon 4.4.5 - Local File Inclusion
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini
28RIESGO
abrir ↗Exploit-DB
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote at
23RIESGO
abrir ↗Exploit-DB
Microsoft Internet Explorer - MSHTML!CMultiReadStreamLifetimeManager::ReleaseThreadStateInternal Read AV
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet E
35RIESGO
abrir ↗Exploit-DB
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH
23RIESGO
abrir ↗Exploit-DB
GitLab - 'impersonate' Feature Privilege Escalation
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8
28RIESGO
abrir ↗Exploit-DB
Claroline < 1.7.7 - Arbitrary File Inclusion
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeo
28RIESGO
abrir ↗Exploit-DB
SquirrelMail < 1.4.7 - Arbitrary Variable Overwrite
Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overw
23RIESGO
abrir ↗Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remot
60RIESGO
abrir ↗Exploit-DB
SAP SAPCAR - Multiple Vulnerabilities
SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to ca
23RIESGO
abrir ↗Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users v
45RIESGO
abrir ↗Exploit-DB
vBulletin 5.2.2 - Server-Side Request Forgery
The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Le
28RIESGO
abrir ↗Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependen
50RIESGO
abrir ↗Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.