Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.460 exploits
Exploit-DB
Cibele Thinfinity VirtualUI 2.5.41.0 - User Enumeration
In Cibele Thinfinity VirtualUI before 3.0, /changePassword returns different responses for invalid authentication reques
43RIESGO
abrir ↗Exploit-DB
Apache Log4j2 2.14.1 - Information Disclosure
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗Exploit-DB
Apache Log4j 2 - Remote Code Execution (RCE)
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
100RIESGO
abrir ↗Exploit-DB
Booked Scheduler 2.7.5 - Remote Command Execution (RCE) (Authenticated)
phpscheduleit Booked Scheduler 2.7.5 allows arbitrary file upload via the Favicon field, leading to execution of arbitra
28RIESGO
abrir ↗Exploit-DB
WebHMI 4.0 - Remote Code Execution (RCE) (Authenticated)
Distributed Data Systems WebHM
60RIESGO
abrir ↗Exploit-DB
HD-Network Real-time Monitoring System 2.0 - Local File Inclusion (LFI)
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_L
50RIESGO
abrir ↗Exploit-DB
Grafana 8.3.0 - Directory Traversal and Arbitrary File Read
Grafana path traversal
100RIESGO
abrir ↗Exploit-DB
Student Management System 1.0 - SQLi Authentication Bypass
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (
28RIESGO
abrir ↗Exploit-DB
Raspberry Pi 5.10 - Default Credentials
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not changed, attackers can gain a
28RIESGO
abrir ↗Exploit-DB
Auerswald COMpact 8.0B - Multiple Backdoors
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web
60RIESGO
abrir ↗Exploit-DB
Croogo 3.0.2 - Remote Code Execution (Authenticated)
A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malic
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin DZS Zoomsounds 6.45 - Arbitrary File Read (Unauthenticated)
ZoomSounds <= 6.45 Unauthenticated Directory Traversal and Sensitive Information Dislosure
68RIESGO
abrir ↗Exploit-DB
Online Enrollment Management System in PHP and PayPal 1.0 - 'U_NAME' Stored Cross-Site Scripting
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an
23RIESGO
abrir ↗Exploit-DB
Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗Exploit-DB
GitLab 13.10.2 - Remote Code Execution (RCE) (Unauthenticated)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validati
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SuiteCRM 7.11.18 - Remote Code Execution (RCE) (Authenticated) (Metasploit)
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumsta
50RIESGO
abrir ↗Exploit-DB
Bludit 3.13.1 - 'username' Cross Site Scripting (XSS)
Cross Site Scripting (XSS) vulnerability exists in bludit 3-13-1 via the username in admin/login.
38RIESGO
abrir ↗Exploit-DB
Online Learning System 2.0 - Remote Code Execution (RCE)
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/adm
23RIESGO
abrir ↗Exploit-DB
Simple Subscription Website 1.0 - SQLi Authentication Bypass
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
23RIESGO
abrir ↗Exploit-DB
PHP Laravel 8.70.1 - Cross Site Scripting (XSS) to Cross Site Request Forgery (CSRF)
Laravel Framework through 8.70.2 does not sufficiently block the upload of executable PHP content because Illuminate/Val
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin WPSchoolPress 2.1.16 - 'Multiple' Cross Site Scripting (XSS)
WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site Scripting
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache HTTP Server 2.4.50 - Remote Code Execution (RCE) (3)
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RIESGO
abrir ↗Exploit-DB
FormaLMS 2.4.4 - Authentication Bypass
An authentication bypass issue in FormaLMS <= 2.4.4 allows an attacker to bypass the authentication mechanism and obtain
28RIESGO
abrir ↗Exploit-DB
FusionPBX 4.5.29 - Remote Code Execution (RCE) (Authenticated)
An issue was discovered in FusionPBX before 4.5.30. The fax_extension may have risky characters (it is not constrained t
35RIESGO
abrir ↗Exploit-DB
Eclipse Jetty 11.0.5 - Sensitive File Disclosure
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characte
70RIESGO
abrir ↗Exploit-DB
OpenAM 13.0 - LDAP Injection
ForgeRock OpenAM before 13.5.1 allows LDAP injection via the Webfinger protocol. For example, an unauthenticated attacke
60RIESGO
abrir ↗Exploit-DB
Fuel CMS 1.4.1 - Remote Code Execution (3)
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir ↗Exploit-DB
WebCTRL OEM 6.5 - 'locale' Reflected Cross-Site Scripting (XSS)
The login portal for the Automated Logic WebCTRL/WebCTRL OEM web application contains a vulnerability that allows for re
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.