Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir ↗Exploit-DB
Piwigo 2.10.1 - Cross Site Scripting
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
28RIESGO
abrir ↗Exploit-DB
ThinkAdmin 6 - Arbitrarily File Read
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CuteNews 2.1.2 - Remote Code Execution
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir ↗Exploit-DB
ZTE Router F602W - Captcha Bypass
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could lo
23RIESGO
abrir ↗Exploit-DB
ManageEngine Applications Manager 14700 - Remote Code Execution (Authenticated)
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in
35RIESGO
abrir ↗Exploit-DB
Rukovoditel 2.7.1 - Remote Code Execution (2) (Authenticated)
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RIESGO
abrir ↗Exploit-DB
Mida eFramework 2.9.0 - Remote Code Execution
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
60RIESGO
abrir ↗Exploit-DB
Microsoft SharePoint Server 2019 - Remote Code Execution
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir ↗Exploit-DB
Artica Proxy 4.3.0 - Authentication Bypass
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p
60RIESGO
abrir ↗Exploit-DB
ACTi NVR3 Standard or Professional Server 3.0.12.42 - Denial of Service (PoC)
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer
28RIESGO
abrir ↗Exploit-DB
Pi-hole 4.3.2 - Remote Code Execution (Authenticated)
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir ↗Exploit-DB
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RIESGO
abrir ↗Exploit-DB
Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
23RIESGO
abrir ↗Exploit-DB
Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir ↗Exploit-DB
F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injection (Unauthenticated)
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RIESGO
abrir ↗Exploit-DB
Rails 5.0.1 - Remote Code Execution
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RIESGO
abrir ↗Exploit-DB
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File Download
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa
70RIESGO
abrir ↗Exploit-DB
Bludit 3.9.2 - Directory Traversal
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir ↗Exploit-DB
pfSense 2.4.4-p3 - Cross-Site Request Forgery
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executi
35RIESGO
abrir ↗Exploit-DB
Bio Star 2.8.2 - Local File Inclusion
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary fi
50RIESGO
abrir ↗Exploit-DB
ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
23RIESGO
abrir ↗Exploit-DB
INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RIESGO
abrir ↗Exploit-DB
Docsify.js 4.11.4 - Reflective Cross-Site Scripting
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a
23RIESGO
abrir ↗Exploit-DB
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
23RIESGO
abrir ↗Exploit-DB
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
23RIESGO
abrir ↗Exploit-DB
CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
23RIESGO
abrir ↗Exploit-DB
Zyxel Armor X1 WAP6806 - Directory Traversal
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.