Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
VestaCP 0.9.8 - File Upload CSRF
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow
23RIESGO
abrir ↗Exploit-DB
Zenario CMS 8.8.53370 - 'id' Blind SQL Injection
SQL Injection in Tribalsystems Zenario CMS 8.8.52729 allows remote attackers to access the database or delete the plugin
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SonLogger 4.2.3.3 - Unauthenticated Arbitrary File Upload (Metasploit)
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Con
50RIESGO
abrir ↗Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Exploit-DB
Microsoft Exchange 2019 - Server-Side Request Forgery (Proxylogon) (PoC)
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir ↗Exploit-DB
Atlassian JIRA 8.11.1 - User Enumeration
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Golden FTP Server 4.70 - 'PASS' Buffer Overflow (2)
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RIESGO
abrir ↗Exploit-DB
Joomla JCK Editor 6.4.4 - 'parent' SQL Injection (2)
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RIESGO
abrir ↗Exploit-DB
e107 CMS 2.3.0 - CSRF
usersettings.php in e107 through 2.3.0 lacks a certain e_TOKEN protection mechanism.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AnyDesk 5.5.2 - Remote Code Execution
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zen Cart 1.5.7b - Remote Code Execution (Authenticated)
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RIESGO
abrir ↗Exploit-DB
Tiny Tiny RSS - Remote Code Execution
An issue was discovered in Tiny Tiny RSS (aka tt-rss) before 2020-09-16. It does not validate all URLs before requesting
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit)
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RIESGO
abrir ↗Exploit-DB
VMware vCenter Server 7.0 - Unauthenticated File Upload
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin. A malicious actor
100RIESGO
abrir ↗Exploit-DB
Monica 2.19.1 - 'last_name' Stored XSS
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
23RIESGO
abrir ↗Exploit-DB
TestLink 1.9.20 - Unrestricted File Upload (Authenticated)
An unrestricted file upload vulnerability in keywordsImport.php in TestLink 1.9.20 allows remote attackers to execute ar
28RIESGO
abrir ↗Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution (2)
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RIESGO
abrir ↗Exploit-DB
Adobe Connect 10 - Username Disclosure
Adobe Connect Improper Access Control Security feature bypass
70RIESGO
abrir ↗Exploit-DB
Alt-N MDaemon webmail 20.0.0 - 'file name' Stored Cross Site Scripting (XSS)
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code
23RIESGO
abrir ↗Exploit-DB
Alt-N MDaemon webmail 20.0.0 - 'Contact name' Stored Cross Site Scripting (XSS)
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19
23RIESGO
abrir ↗Exploit-DB
Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (1)
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗Exploit-DB
Sudo 1.9.5p1 - 'Baron Samedit ' Heap-Based Buffer Overflow Privilege Escalation (2)
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗Exploit-DB
Pixelimity 1.0 - 'password' Cross-Site Request Forgery
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
23RIESGO
abrir ↗Exploit-DB
Klog Server 2.4.1 - Command Injection (Authenticated)
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of
35RIESGO
abrir ↗Exploit-DB
MyBB Hide Thread Content Plugin 1.0 - Information Disclosure
The Hide-Thread-Content plugin through 2021-01-27 for MyBB allows remote attackers to bypass intended content-reading re
28RIESGO
abrir ↗Exploit-DB
Quick.CMS 6.7 - Remote Code Execution (Authenticated)
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequentl
28RIESGO
abrir ↗Exploit-DB
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. A
23RIESGO
abrir ↗Exploit-DB
CMSUno 1.6.2 - 'lang' Remote Code Execution (Authenticated)
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and r
23RIESGO
abrir ↗Exploit-DB
Metasploit Framework 6.0.11 - msfvenom APK template command injection
Client-Side Command Injection in Rapid7 Metasploit
68RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.