Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8649Nuclei 4283Metasploit 3474✓ solo verificadosrecientespopularesriesgo
77.401 exploits
Exploit-DB
Centos Web Panel 7 v0.9.8.1147 - Unauthenticated Remote Code Execution (RCE)
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RIESGO
abrir ↗Exploit-DB
perfSONAR v4.4.5 - Partial Blind CSRF
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attack
33RIESGO
abrir ↗Exploit-DB
TP-Link TL-WR902AC firmware 210730 (V3) - Remote Code Execution (RCE) (Authenticated)
TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a De
53RIESGO
abrir ↗Exploit-DB
Reprise Software RLM v14.2BL4 - Cross-Site Scripting (XSS)
XSS in signing form in Reprise Software RLM License Administration v14.2BL4 allows remote attacker to inject arbitrary c
33RIESGO
abrir ↗Exploit-DB
EQ Enterprise management system v2.2.0 - SQL Injection
EQ v1.5.31 to v2.2.0 was discovered to contain a SQL injection vulnerability via the UserPwd parameter.
48RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗Exploit-DB
rconfig 3.9.7 - Sql Injection (Authenticated)
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may
41RIESGO
abrir ↗GitHub PoC
webmin <=1.920 - RCE via command injection vulnerability
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir ↗Exploit-DB
Cacti v1.2.22 - Remote Command Execution (RCE)
Unauthenticated Command Injection
100RIESGO
abrir ↗Metasploit500
Zyxel IKE Packet Decoder Unauthenticated Remote Code Execution
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2023-23397漏洞的简单PoC,有效载荷通过电子邮件发送。
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir ↗Exploit-DB
qubes-mirage-firewall v0.8.3 - Denial Of Service (DoS)
qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of s
61RIESGO
abrir ↗GitHub PoC
turnernator1/Node.js-CVE-2017-5941
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RIESGO
abrir ↗Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during f
28RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue in WooCommerce Payments plugin for WordPress (versions 5.6.1 and lower) allows an unauthenticated attacker to s
60RIESGO
abrir ↗Exploit-DB
LISTSERV 17 - Reflected Cross Site Scripting (XSS)
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary
48RIESGO
abrir ↗GitHub PoC★ 1
ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS
ZCBS Zijper Collectie Beheer Systeem (ZCBS), Zijper Publication Management System (ZPBS), and Zijper Image Bank Manageme
33RIESGO
abrir ↗Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh
28RIESGO
abrir ↗Exploit-DB
CrowdStrike Falcon AGENT 6.44.15806 - Uninstall without Installation Token
CrowdStrike Falcon Uninstallation authorization
28RIESGO
abrir ↗Exploit-DB
LISTSERV 17 - Insecure Direct Object Reference (IDOR)
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a
41RIESGO
abrir ↗Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injec
68RIESGO
abrir ↗Metasploit600
Nextcloud Workflows Remote Code Execution
Scope of workflow operations is not validated in nextcloud server
63RIESGO
abrir ↗Metasploit400
Rocket Software Unidata udadmin_server Stack Buffer Overflow in Password
Stack buffer overflow in UniRPC's udadmin_server service
75RIESGO
abrir ↗Metasploit600
Rocket Software Unidata udadmin_server Authentication Bypass
Authentication bypass in UniRPC's udadmin service
75RIESGO
abrir ↗Exploit-DB
Device Manager Express 7.8.20002.47752 - Remote Code Execution (RCE)
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achie
60RIESGO
abrir ↗GitHub PoC
0759104103/cd-CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir ↗GitHub PoC★ 1
Full LPE Exploit for CVE-2019-5596 / FreeBSD-SA-19:02.fd
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WP All Import v3.6.7 - Remote Code Execution (RCE) (Authenticated)
Import any XML or CSV File to WordPress <= 3.6.7 - Admin+ Malicious File Upload
46RIESGO
abrir ↗GitHub PoC
jacquesquail/CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.