Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
htmly 2.8.0 - 'description' Stored Cross-Site Scripting (XSS)
htmly 2.8.0 allows stored XSS via the blog title, Tagline, or Description to config.html.php.
23RIESGO
abrir ↗Exploit-DB
jQuery 1.2 - Cross-Site Scripting (XSS)
jQuery has a potential XSS vulnerability
55RIESGO
abrir ↗Exploit-DB
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 - RCE
Genexis PLATINUM 4410 2.1 P4410-V2-1.28 devices allow remote attackers to execute arbitrary code via shell metacharacter
35RIESGO
abrir ↗Exploit-DB
CITSmart ITSM 9.1.2.22 - LDAP Injection
CITSmart before 9.1.2.23 allows LDAP Injection.
28RIESGO
abrir ↗Exploit-DB
CITSmart ITSM 9.1.2.27 - 'query' Time-based Blind SQL Injection (Authenticated)
CITSmart before 9.1.2.28 mishandles the "filtro de autocomplete."
23RIESGO
abrir ↗Exploit-DB
MariaDB 10.2 - 'wsrep_provider' OS Command Execution
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, a
35RIESGO
abrir ↗Exploit-DB
jQuery 1.0.3 - Cross-Site Scripting (XSS)
Potential XSS vulnerability in jQuery
85RIESGO
abrir ↗Exploit-DB
ExpressVPN VPN Router 1.0 - Router Login Panel's Integer Overflow
An integer buffer overflow in the Nginx webserver of ExpressVPN Router version 1 allows remote attackers to obtain sensi
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir ↗Exploit-DB
PrestaShop 1.7.6.7 - 'location' Blind Sql Injection
Blind SQL Injection in PrestaShop
28RIESGO
abrir ↗Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via a
23RIESGO
abrir ↗Exploit-DB
DMA Radius Manager 4.4.0 - Cross-Site Request Forgery (CSRF)
DMA Softlab Radius Manager 4.4.0 allows CSRF with impacts such as adding new manager accounts via admin.php.
23RIESGO
abrir ↗Exploit-DB
Composr 10.0.36 - Remote Code Execution
Composr 10.0.36 allows upload and execution of PHP files.
28RIESGO
abrir ↗Exploit-DB
Linux Kernel 5.4 - 'BleedingTooth' Bluetooth Zero-Click Remote Code Execution
Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adja
23RIESGO
abrir ↗Exploit-DB
Dell OpenManage Server Administrator 9.4.0.0 - Arbitrary File Read
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RIESGO
abrir ↗Exploit-DB
Composr CMS 10.0.36 - Cross Site Scripting
Composr 10.0.36 allows XSS in an XML script.
23RIESGO
abrir ↗Exploit-DB
Atlassian Jira Service Desk 4.9.1 - Unrestricted File Upload to XSS
The /servicedesk/customer/portals resource in Jira Service Desk Server and Data Center before version 4.10.0 allows remo
23RIESGO
abrir ↗Exploit-DB
Google Chrome 81.0.4044 V8 - Remote Code Execution
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap
28RIESGO
abrir ↗Exploit-DB
Google Chrome 86.0.4240 V8 - Remote Code Execution
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir ↗Exploit-DB
F5 BIG-IP 16.0.x - iControl REST Remote Code Execution (Unauthenticated)
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir ↗Exploit-DB
SyncBreeze 10.1.16 - XML Parsing Stack-based Buffer Overflow
Flexense SyncBreeze Enterprise version 10.1.16 is vulnerable to a buffer overflow that can be exploited for arbitrary co
23RIESGO
abrir ↗Exploit-DB
Concrete5 8.5.4 - 'name' Stored XSS
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.p
23RIESGO
abrir ↗Exploit-DB
Linksys EA7500 2.0.8.194281 - Cross-Site Scripting
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RIESGO
abrir ↗Exploit-DB
Dolibarr ERP 11.0.4 - File Upload Restrictions Bypass (Authenticated RCE)
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code executio
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Codiad 2.8.4 - Remote Code Execution (Authenticated)
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RIESGO
abrir ↗Exploit-DB
MyBB 1.8.25 - Poll Vote Count SQL Injection
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RIESGO
abrir ↗Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
SQL Injection vulnerablity in MyBB before 1.8.26 via theme properties included in theme XML files.
28RIESGO
abrir ↗Exploit-DB
MyBB 1.8.25 - Chained Remote Command Execution
Cross-site Scripting (XSS) vulnerability in MyBB before 1.8.26 via Nested Auto URL when parsing messages.
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path Traversal
jqueryFileTree 2.1.5 and older Directory Traversal
50RIESGO
abrir ↗Exploit-DB
LiveZilla Server 8.0.1.0 - 'Accept-Language' Reflected XSS
LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header.
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.