Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.497GitHub PoC 13.627VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB
RedaxScript CMS 2.2.0 - SQL Injection
SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote
23RIESGO
abrir ↗Exploit-DB
Fork CMS 3.8.5 - SQL Injection
Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to exec
23RIESGO
abrir ↗Exploit-DB
u5CMS 3.9.3 - 'deletefile.php' Arbitrary File Deletion
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to ar
23RIESGO
abrir ↗Exploit-DB
u5CMS 3.9.3 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Exploit-DB
ManageEngine OpManager / Applications Manager / IT360 - 'FailOverServlet' Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in the FailOverHelperServlet (aka FailServlet) servlet in ZOHO ManageEngine OpMan
28RIESGO
abrir ↗Exploit-DB
Achat 0.150 beta7 - Remote Buffer Overflow
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web s
23RIESGO
abrir ↗Exploit-DB
Achat 0.150 beta7 - Remote Buffer Overflow
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to ar
23RIESGO
abrir ↗Exploit-DB
Magento Server MAGMI Plugin - Multiple Vulnerabilities
Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento
50RIESGO
abrir ↗Exploit-DB
Magento Server MAGMI Plugin - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server a
43RIESGO
abrir ↗Exploit-DB
AVG Internet Security 2015.0.5315 - Arbitrary Write Privilege Escalation
The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protec
23RIESGO
abrir ↗Exploit-DB
K7 Computing (Multiple Products) - Arbitrary Write Privilege Escalation
K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users
23RIESGO
abrir ↗Exploit-DB
BullGuard (Multiple Products) - Arbitrary Write Privilege Escalation
bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows loca
23RIESGO
abrir ↗Exploit-DB
Pragyan CMS 3.0 - SQL Injection
SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass
HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to o
35RIESGO
abrir ↗Exploit-DB
ManageEngine Desktop Central 9 Build 90087 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Remote Desktop Services - Web Proxy IE Sandbox Escape (MS15-004) (Metasploit)
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir ↗Exploit-DB
Sefrengo CMS 1.6.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB
Symantec Altiris Agent 6.9 (Build 648) - Local Privilege Escalation
Buffer overflow in AClient in Symantec Deployment Solution 6.9 and earlier on Windows XP and Server 2003 allows local us
23RIESGO
abrir ↗Exploit-DB
Trend Micro 8.0.1133 (Multiple Products) - Local Privilege Escalation
The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows lo
23RIESGO
abrir ↗Exploit-DB
McAfee Data Loss Prevention Endpoint - Arbitrary Write Privilege Escalation
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, an
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector 8.x - Remote Command Execution
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Encryption Management Server < 3.2.0 MP6 - Remote Command Injection
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrator
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows Server 2003 SP2 - Local Privilege Escalation (MS14-070)
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir ↗Exploit-DB
ManageEngine Firewall Analyzer 8.0 - Directory Traversal / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inje
38RIESGO
abrir ↗Exploit-DB
Apple Mac OSX < 10.10.x - GateKeeper Bypass
LaunchServices in Apple OS X before 10.10.2 does not properly handle file-type metadata, which allows attackers to bypas
23RIESGO
abrir ↗Exploit-DB
ManageEngine Firewall Analyzer 8.0 - Directory Traversal / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers t
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - Multiple Vulnerabilities
Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 be
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - Multiple Vulnerabilities
Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows
23RIESGO
abrir ↗Exploit-DB
Exim ESMTP 4.80 - glibc gethostbyname Denial of Service
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir ↗Exploit-DB
jclassifiedsmanager - Multiple Vulnerabilities
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execu
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.