Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.523GitHub PoC 14.289VulnCheck XDB 8710Nuclei 4319Metasploit 3476✓ solo verificadosrecientespopularesriesgo
22.492 exploits
Referência
CVE-2017-2935
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the F
28RIESGO
abrir ↗Referência
CVE-2017-2933
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture co
28RIESGO
abrir ↗Referência
CVE-2017-2934
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Te
28RIESGO
abrir ↗Referência
CVE-2018-12636
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi
35RIESGO
abrir ↗Referência
CVE-2016-8527
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). Th
43RIESGO
abrir ↗Referência✓ VexDay Proof
Microsoft Windows Mobile 6.0 - Device Long Name Remote Reboot (Denial of Service)
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to esta
35RIESGO
abrir ↗Referência
CVE-2009-1699
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for i
28RIESGO
abrir ↗Referência
CVE-2017-11517
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RIESGO
abrir ↗Referência
CVE-2019-7274
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
28RIESGO
abrir ↗Referência
CVE-2018-12327
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or es
28RIESGO
abrir ↗Referência
CVE-2018-14058
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RIESGO
abrir ↗Referência
CVE-2018-14058
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RIESGO
abrir ↗Referência
CVE-2011-4642
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python
43RIESGO
abrir ↗Referência
CVE-2013-3238
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a
43RIESGO
abrir ↗Referência
CVE-2009-3753
Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a fil
23RIESGO
abrir ↗Referência
CVE-2018-19571
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RIESGO
abrir ↗Referência
CVE-2015-7766
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RIESGO
abrir ↗Referência
CVE-2015-7766
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RIESGO
abrir ↗Referência
CVE-2019-19356
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.
76RIESGO
abrir ↗Referência
CVE-2015-3036
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RIESGO
abrir ↗Referência
CVE-2013-3632
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users
68RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Dada Mail Manager 2.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in config.dadamail.php in the Dada Mail Manager (com_dadamail) component 2.6 for
35RIESGO
abrir ↗Referência
CVE-2015-7808
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir ↗Referência
Persian VIP Download Script 1.0 - 'active' SQL Injection
Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.
23RIESGO
abrir ↗Referência
CVE-2015-2521
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to exec
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.