Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
Metasploit Framework 6.0.11 - msfvenom APK template command injection
Client-Side Command Injection in Rapid7 Metasploit
68RIESGO
abrir ↗Exploit-DB
Tenda AC5 AC1200 Wireless - 'WiFi Name & Password' Stored Cross Site Scripting
A Stored Cross-site scripting (XSS) vulnerability in /main.html Wifi Settings in Tenda AC5 AC1200 version V15.03.06.47_m
23RIESGO
abrir ↗Exploit-DB
Oracle WebLogic Server 12.2.1.0 - RCE (Unauthenticated)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Klog Server 2.4.1 - Unauthenticated Command Injection (Metasploit)
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RIESGO
abrir ↗Exploit-DB
Oracle WebLogic Server 14.1.1.0 - RCE (Authenticated)
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RIESGO
abrir ↗Exploit-DB
Atlassian Confluence Widget Connector Macro - SSTI
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir ↗Exploit-DB
Anchor CMS 0.12.7 - CSRF (Delete user)
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wordpress Plugin Simple Job Board 2.9.3 - Authenticated File Read (Metasploit)
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RIESGO
abrir ↗Exploit-DB
osTicket 1.14.2 - SSRF
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
60RIESGO
abrir ↗Exploit-DB
Nagios XI 5.7.X - Remote Code Execution RCE (Authenticated)
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir ↗Exploit-DB
Laravel 8.4.2 debug mode - Remote code execution
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PaperStream IP (TWAIN) 1.42.0.5685 - Local Privilege Escalation
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes u
23RIESGO
abrir ↗Exploit-DB
IPeakCMS 3.5 - Boolean-based blind SQLi
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Gitea 1.7.5 - Remote Code Execution
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to rem
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir ↗Exploit-DB
Fluentd TD-agent plugin 4.0.1 - Insecure Folder Permission
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory
23RIESGO
abrir ↗Exploit-DB
IncomCMS 2.0 - Insecure File Upload
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows un
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Klog Server 2.4.1 - Command Injection (Unauthenticated)
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RIESGO
abrir ↗Exploit-DB
Subrion CMS 4.2.1 - 'avatar[path]' XSS
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the
23RIESGO
abrir ↗Exploit-DB
Advanced Comment System 1.0 - 'ACS_path' Path Traversal
ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=.
43RIESGO
abrir ↗Exploit-DB
Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A
33RIESGO
abrir ↗Exploit-DB
Wordpress Core 5.2.2 - 'post previews' XSS
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
23RIESGO
abrir ↗Exploit-DB
GitLab 11.4.7 - RCE (Authenticated) (2)
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection
28RIESGO
abrir ↗Exploit-DB
GitLab 11.4.7 - RCE (Authenticated) (2)
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RIESGO
abrir ↗Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table
23RIESGO
abrir ↗Exploit-DB
Spiceworks 7.5 - HTTP Header Injection
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we
23RIESGO
abrir ↗Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Tab
23RIESGO
abrir ↗Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Cha
23RIESGO
abrir ↗Exploit-DB
SCO Openserver 5.0.7 - 'section' Reflected XSS
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.