Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.458 exploits
Exploit-DB
HPE Intelligent Management Center < 7.3 E0506P09 - Information Disclosure
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RIESGO
abrir ↗Exploit-DB
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RIESGO
abrir ↗Exploit-DB
Gila CMS < 1.11.1 - Local File Inclusion
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
23RIESGO
abrir ↗Exploit-DB
vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir ↗Exploit-DB
LayerBB < 1.1.4 - Cross-Site Request Forgery
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
23RIESGO
abrir ↗Exploit-DB
Western Digital My Book World II NAS 1.02.12 - Authentication Bypass / Command Execution
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to acce
23RIESGO
abrir ↗Exploit-DB
Counter-Strike Global Offensive 1.37.1.1 - 'vphysics.dll' Denial of Service (PoC)
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or de
23RIESGO
abrir ↗Exploit-DB
Notepad++ < 7.7 (x64) - Denial of Service
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch
23RIESGO
abrir ↗Exploit-DB
AppXSvc - Privilege Escalation
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir ↗Exploit-DB
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A
23RIESGO
abrir ↗Exploit-DB
Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft DirectWrite - Invalid Read in SplicePixel While Processing OTF Fonts
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft DirectWrite - Out-of-Bounds Read in sfac_GetSbitBitmap While Processing TTF Fonts
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
October CMS - Upload Protection Bypass Code Execution (Metasploit)
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LibreNMS - Collectd Command Injection (Metasploit)
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev
60RIESGO
abrir ↗Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - SQL Injection
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2)
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi
23RIESGO
abrir ↗Exploit-DB
Enigma NMS 65.0.0 - OS Command Injection
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows
43RIESGO
abrir ↗Exploit-DB
Enigma NMS 65.0.0 - SQL Injection
A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows a
23RIESGO
abrir ↗Exploit-DB
Enigma NMS 65.0.0 - Cross-Site Request Forgery
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to tri
23RIESGO
abrir ↗Exploit-DB
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Remote Code Execution
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir ↗Exploit-DB
FusionPBX 4.4.8 - Remote Code Execution
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AwindInc SNMP Service - Command Injection (Metasploit)
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote
60RIESGO
abrir ↗Exploit-DB
WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t
53RIESGO
abrir ↗Exploit-DB
DASAN Zhone ZNID GPON 2426A EU - Multiple Cross-Site Scripting
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devic
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
Cisco Data Center Network Manager Information Disclosure Vulnerability
70RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco RV110W/RV130(W)/RV215W Routers Management Interface - Remote Command Execution (Metasploit)
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.