Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB
Hawkeye-G 3.0.1.4912 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SysAid Help Desk 'rdslogs' - Arbitrary File Upload (Metasploit)
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir ↗Exploit-DB
Internet Download Manager - OLE Automation Array Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Exploit-DB
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote att
23RIESGO
abrir ↗Exploit-DB
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read ar
50RIESGO
abrir ↗Exploit-DB
XPCOM - Race Condition
Race condition in the xpcom library, as used by web browsers such as Firefox, Mozilla, Netscape, and Galeon, allows remo
23RIESGO
abrir ↗Exploit-DB
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to exe
23RIESGO
abrir ↗Exploit-DB
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted
23RIESGO
abrir ↗Exploit-DB
Joomla! Component Helpdesk Pro < 1.4.0 - Multiple Vulnerabilities
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users
23RIESGO
abrir ↗Exploit-DB
Microsoft Word - Local Machine Zone Code Execution (MS15-022)
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 all
35RIESGO
abrir ↗Exploit-DB
TcpDump - rpki_rtr_pdu_print Out-of-Bounds Denial of Service
The rpki_rtr_pdu_print function in print-rpki-rtr.c in the TCP printer in tcpdump before 4.7.2 allows remote attackers t
28RIESGO
abrir ↗Exploit-DB
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (1)
Directory traversal vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18,
23RIESGO
abrir ↗Exploit-DB
Kaseya Virtual System Administrator (VSA) - Multiple Vulnerabilities (1)
Open redirect vulnerability in Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.29, 8.x before 8.0.0.18, 9.0 b
43RIESGO
abrir ↗Exploit-DB
SquirrelMail < 1.4.5-RC1 - Arbitrary Variable Overwrite
options_identities.php in SquirrelMail 1.4.4 and earlier uses the extract function to process the $_POST variable, which
23RIESGO
abrir ↗Exploit-DB
sysPass 1.0.9 - SQL Injection
SQL injection vulnerability in cygnux.org sysPass 1.0.9 and earlier allows remote authenticated users to execute arbitra
23RIESGO
abrir ↗Exploit-DB
Pimcore CMS Build 3450 - Directory Traversal
Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permi
23RIESGO
abrir ↗Exploit-DB
FreiChat 9.6 - SQL Injection
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows
23RIESGO
abrir ↗Exploit-DB
ArticleFR 3.0.6 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers t
23RIESGO
abrir ↗Exploit-DB
ZenPhoto 1.4.8 - Multiple Vulnerabilities
SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
23RIESGO
abrir ↗Exploit-DB
ZenPhoto 1.4.8 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack
23RIESGO
abrir ↗Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
Multiple SQL vulnerabilities exist in planning.php, user_list.php, projets.php, user_groupes.php, and groupe_list.php in
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Swim Team 1.44.10777 - Arbitrary File Download
Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allo
50RIESGO
abrir ↗Exploit-DB
ArticleFR 3.0.6 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Free Reprintables ArticleFR 3.0.6 allow remote attackers to injec
23RIESGO
abrir ↗Exploit-DB
ZenPhoto 1.4.8 - Multiple Vulnerabilities
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Accellion FTA - getStatus verify_oauth_token Command Execution (Metasploit)
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach
60RIESGO
abrir ↗Exploit-DB
Arab Portal 3 - SQL Injection
SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail
23RIESGO
abrir ↗Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and
23RIESGO
abrir ↗Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which all
28RIESGO
abrir ↗Exploit-DB
SO Planning 1.32 - Multiple Vulnerabilities
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Western Digital Arkeia < 11.0.12 - Remote Code Execution (Metasploit)
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to b
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.