Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RIESGO
abrir ↗Exploit-DB
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ins
100RIESGO
abrir ↗Exploit-DB
Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RIESGO
abrir ↗Exploit-DB
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bludit 3.9.2 - Auth Bruteforce Bypass
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir ↗Exploit-DB
HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo
35RIESGO
abrir ↗Exploit-DB
Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir ↗Exploit-DB
HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthentic
28RIESGO
abrir ↗Exploit-DB
HiSilicon Video Encoders - Full admin access via backdoor password
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use har
28RIESGO
abrir ↗Exploit-DB
HiSilicon Video Encoders - RCE via unauthenticated command injection
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo
35RIESGO
abrir ↗Exploit-DB
HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a
35RIESGO
abrir ↗Exploit-DB
Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RIESGO
abrir ↗Exploit-DB
Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RIESGO
abrir ↗Exploit-DB
Seat Reservation System 1.0 - Unauthenticated SQL Injection
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RIESGO
abrir ↗Exploit-DB
Cisco ASA and FTD 9.6.4.42 - Path Traversal
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir ↗Exploit-DB
Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, lea
23RIESGO
abrir ↗Exploit-DB
D-Link DSR-250N 3.12 - Denial of Service (PoC)
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed
28RIESGO
abrir ↗Exploit-DB
SpamTitan 7.07 - Unauthenticated Remote Code Execution
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RIESGO
abrir ↗Exploit-DB
Mida eFramework 2.8.9 - Remote Code Execution
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)
35RIESGO
abrir ↗Exploit-DB
MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RIESGO
abrir ↗Exploit-DB
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
23RIESGO
abrir ↗Exploit-DB
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir ↗Exploit-DB
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote
23RIESGO
abrir ↗Exploit-DB
Mida eFramework 2.9.0 - Back Door Access
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric
28RIESGO
abrir ↗Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php woul
23RIESGO
abrir ↗Exploit-DB
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
35RIESGO
abrir ↗Exploit-DB
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RIESGO
abrir ↗Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page ma
23RIESGO
abrir ↗Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.
23RIESGO
abrir ↗Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with th
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.