Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB
XOOPS < 2.0.11 - Multiple Vulnerabilities
SQL injection vulnerability in the loginUser function in the XMLRPC server in XOOPS 2.0.11 and earlier allows remote att
23RIESGO
abrir ↗Exploit-DB
XOOPS < 2.0.11 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 2.0.11 and earlier allow remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB
DeDeCMS < 5.7-sp1 - Remote File Inclusion
A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.
35RIESGO
abrir ↗Exploit-DB
Endian Firewall < 3.0.0 - OS Command Injection
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir ↗Exploit-DB
Endian Firewall < 3.0.0 - OS Command Injection (Metasploit)
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Havij - OLE Automation Array Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Exploit-DB
ManageEngine Asset Explorer 6.1 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 allows remote attacker
23RIESGO
abrir ↗Exploit-DB
Koha 3.20.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and
23RIESGO
abrir ↗Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RIESGO
abrir ↗Exploit-DB
Thycotic Secret Server 8.8.000004 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the basic dashboard in Thycotic Secret Server 8.6.x, 8.7.x, and 8.8.x before
23RIESGO
abrir ↗Exploit-DB
Koha 3.20.1 - Multiple Cross-Site Scripting / Cross-Site Request Forgery Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x
23RIESGO
abrir ↗Exploit-DB
Koha 3.20.1 - Directory Traversal
Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08
50RIESGO
abrir ↗Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Vesta Control Panel 0.9.8 - OS Command Injection
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - ClientCopyImage Win32k (MS15-051) (Metasploit)
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - ShaderJob Buffer Overflow (Metasploit)
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
60RIESGO
abrir ↗Exploit-DB
GeniXCMS 0.0.3 - 'register.php' SQL Injection
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote
23RIESGO
abrir ↗Exploit-DB
GeniXCMS 0.0.3 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject ar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allow attackers to execute arbitrary code
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.png' Parsing Memory Corruption
Heap-based buffer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Photoshop CC2014 / Bridge CC 2014 - '.gif' Parsing Memory Corruption
Integer overflow in Adobe Photoshop CC before 16.0 (aka 2015.0.0) and Adobe Bridge CC before 6.11 allows attackers to ex
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS < 2.0.3 - Multiple Vulnerabilities
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tango DropBox 3.1.5 + PRO - Activex HeapSpray
Buffer overflow in the GetWebStoreURL function in a certain ActiveX control in eSellerateControl365.dll 3.6.5.0 in eSell
23RIESGO
abrir ↗Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to writ
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lively Cart - SQL Injection
SQL injection vulnerability in LivelyCart 1.2.0 allows remote attackers to execute arbitrary SQL commands via the search
23RIESGO
abrir ↗Exploit-DB
ManageEngine SupportCenter Plus 7.90 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Zoho ManageEngine SupportCenter Plus 7.90 allow remote authentica
23RIESGO
abrir ↗Exploit-DB
BlackCat CMS 1.1.1 - Arbitrary File Download
Directory traversal vulnerability in widgets/logs.php in BlackCat CMS before 1.1.2 allows remote attackers to read arbit
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation (Access /etc/shadow)
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.13.0 < 3.19 (Ubuntu 12.04/14.04/14.10/15.04) - 'overlayfs' Local Privilege Escalation
The overlayfs implementation in the linux (aka Linux kernel) package before 3.19.0-21.21 in Ubuntu through 15.04 does no
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ruby on Rails 4.0.x/4.1.x/4.2.x (Web Console v2) - Whitelist Bypass Code Execution (Metasploit)
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.