Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table
23RIESGO
abrir ↗Exploit-DB
Spiceworks 7.5 - HTTP Header Injection
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we
23RIESGO
abrir ↗Exploit-DB
FRITZ!Box 7.20 - DNS Rebinding Protection Bypass
FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.
23RIESGO
abrir ↗Exploit-DB
Nxlog Community Edition 2.10.2150 - DoS (Poc)
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RIESGO
abrir ↗Exploit-DB
Solaris SunSSH 11.0 x86 - libpam Remote Root
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RIESGO
abrir ↗Exploit-DB
Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir ↗Exploit-DB
GitLab 11.4.7 - Remote Code Execution (Authenticated) (1)
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RIESGO
abrir ↗Exploit-DB
GitLab 11.4.7 - Remote Code Execution (Authenticated) (1)
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection
28RIESGO
abrir ↗Exploit-DB
Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via '
23RIESGO
abrir ↗Exploit-DB
Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a sto
23RIESGO
abrir ↗Exploit-DB
Rukovoditel 2.6.1 - RCE (1)
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RIESGO
abrir ↗Exploit-DB
Jenkins 2.235.3 - 'Description' Stored XSS
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in
45RIESGO
abrir ↗Exploit-DB
SmarterMail Build 6985 - Remote Code Execution
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RIESGO
abrir ↗Exploit-DB
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell)
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a
28RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make
43RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a
28RIESGO
abrir ↗Exploit-DB
Chromium 83 - Full CSP Bypass
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Wp-FileManager 6.8 - RCE
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir ↗Exploit-DB
Anuko Time Tracker 1.19.23.5311 - Password Reset leading to Account Takeover
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an a
23RIESGO
abrir ↗Exploit-DB
WonderCMS 3.1.3 - Authenticated SSRF to Remote Remote Code Execution
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in Wonder
35RIESGO
abrir ↗Exploit-DB
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upl
28RIESGO
abrir ↗Exploit-DB
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Add Artwork
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to uplo
28RIESGO
abrir ↗Exploit-DB
Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial o
23RIESGO
abrir ↗Exploit-DB
WonderCMS 3.1.3 - Authenticated Remote Code Execution
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, al
28RIESGO
abrir ↗Exploit-DB
PRTG Network Monitor 20.4.63.1412 - 'maps' Stored XSS
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can c
23RIESGO
abrir ↗Exploit-DB
Wordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site Scripting
The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.
43RIESGO
abrir ↗Exploit-DB
Joomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File Upload
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating
50RIESGO
abrir ↗Exploit-DB
Rejetto HttpFileServer 2.3.x - Remote Command Execution (3)
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗Exploit-DB
libupnp 1.6.18 - Stack-based buffer overflow (DoS)
Stack-based buffer overflow in the unique_service_name function in ssdp/ssdp_server.c in the SSDP parser in the portable
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.