Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
Optergy 2.3.0a - Remote Code Execution (Backdoor)
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RIESGO
abrir ↗Exploit-DB
eMerge E3 1.00-06 - Remote Code Execution
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir ↗Exploit-DB
Optergy 2.3.0a - Remote Code Execution
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
28RIESGO
abrir ↗Exploit-DB
Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting
A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious Jav
23RIESGO
abrir ↗Exploit-DB
eMerge E3 1.00-06 - Arbitrary File Upload
Linear eMerge E3-Series devices allow Unrestricted File Upload.
35RIESGO
abrir ↗Exploit-DB
FlexAir Access Control 2.3.35 - Authentication Bypass
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu
28RIESGO
abrir ↗Exploit-DB
Atlassian Confluence 6.15.1 - Directory Traversal
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RIESGO
abrir ↗Exploit-DB
eMerge50P 5000P 4.6.07 - Remote Code Execution
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
35RIESGO
abrir ↗Exploit-DB
eMerge E3 1.00-06 - Privilege Escalation
Linear eMerge E3-Series devices allow File Inclusion.
60RIESGO
abrir ↗Exploit-DB
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw
23RIESGO
abrir ↗Exploit-DB
CBAS-Web 19.0.0 - Username Enumeration
Computrols CBAS 18.0.0 allows Username Enumeration.
23RIESGO
abrir ↗Exploit-DB
Optergy 2.3.0a - Username Disclosure
Optergy Proton/Enterprise devices allow Username Disclosure.
28RIESGO
abrir ↗Exploit-DB
eMerge E3 1.00-06 - Cross-Site Request Forgery
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
28RIESGO
abrir ↗Exploit-DB
eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting
Linear eMerge E3-Series devices allow XSS.
50RIESGO
abrir ↗Exploit-DB
Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
23RIESGO
abrir ↗Exploit-DB
Prima Access Control 2.3.35 - Arbitrary File Upload
Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when
28RIESGO
abrir ↗Exploit-DB
Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
23RIESGO
abrir ↗Exploit-DB
CBAS-Web 19.0.0 - Information Disclosure
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
23RIESGO
abrir ↗Exploit-DB
eMerge E3 1.00-06 - Unauthenticated Directory Traversal
Linear eMerge E3-Series devices allow File Inclusion.
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
An out-of-bounds read was addressed with improved input validation.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
rConfig - install Command Execution (Metasploit)
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir ↗Exploit-DB
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir ↗Exploit-DB
Adive Framework 2.0.7 - Privilege Escalation
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Micro Focus (HPE) Data Protector - SUID Privilege Escalation (Metasploit)
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RIESGO
abrir ↗Exploit-DB
Apache Solr 8.2.0 - Remote Code Execution
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.