Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB✓ VexDay Proof
HP Data Protector - Backup Client Service Remote Code Execution (Metasploit)
The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SolidWorks Workgroup PDM 2014 - 'pdmwService.exe' Arbitrary File Write (Metasploit)
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ownCloud 4.0.x/4.5.x - 'upload.php?Filename' Remote Code Execution
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote aut
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNX 6.4.x/6.5.x ifwatchd - Local Privilege Escalation
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arb
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNX 6.4.x/6.5.x pppoectl - Information Disclosure
/sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by rea
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS 4.2.1 - 'facetime-audio://' Security Bypass
TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime au
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GetGo Download Manager 4.9.0.1982 - HTTP Response Header Buffer Overflow Remote Code Execution
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attac
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts < 1.3.10 / < 2.3.16.2 - ClassLoader Manipulation Remote Code Execution (Metasploit)
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir ↗Exploit-DB
Ilch CMS 2.0 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Exploit-DB
OpenDocMan 1.2.7 - Multiple Vulnerabilities
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ALLPlayer - '.m3u' Local Buffer Overflow (Metasploit)
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir ↗Exploit-DB
OpenDocMan 1.2.7 - Multiple Vulnerabilities
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
Multiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrat
23RIESGO
abrir ↗Exploit-DB
SpagoBI 4.0 - Persistent HTML Script Insertion
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
couponPHP CMS 1.0 - Multiple Persistent Cross-Site Scripting / SQL Injections
Multiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execut
23RIESGO
abrir ↗Exploit-DB
SpagoBI 4.0 - Arbitrary Cross-Site Scripting / Arbitrary File Upload
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users
23RIESGO
abrir ↗Exploit-DB
SpagoBI 4.0 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ALLPlayer 5.8.1 - '.m3u' Local Buffer Overflow (SEH)
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Demantra 12.2.1 - SQL Injection
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Demantra 12.2.1 - Arbitrary File Disclosure
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Demantra 12.2.1 - Database Credentials Disclosure
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Demantra 12.2.1 - Persistent Cross-Site Scripting
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Li
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GE Proficy CIMPLICITY - 'gefebt.exe' Remote Code Execution (Metasploit)
GE Proficy HMI/SCADA Path Traversal
78RIESGO
abrir ↗Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharact
23RIESGO
abrir ↗Exploit-DB
Webuzo 2.1.3 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo befor
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin VideoWhisper 4.27.3 - Multiple Vulnerabilities
Unrestricted file upload vulnerability in ls/vw_snapshots.php in the VideoWhisper Live Streaming Integration plugin befo
28RIESGO
abrir ↗Exploit-DB
Plex Media Server 0.9.9.2.374-aa23a69 - Multiple Vulnerabilities
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and e
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.