Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.258exploits catalogados
36.019CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8811Nuclei 4349Metasploit 3488✓ solo verificadosrecientespopularesriesgo
78.258 exploits
Exploit-DB
WordPress Plugin LifterLMS 4.21.0 - Stored Cross-Site Scripting (XSS)
LifterLMS < 4.21.1 - Authenticated Stored XSS in Edit Profile
23RIESGO
abrir ↗GitHub PoC
Detect vulns liferay CVE-2020-7961 by Nattroc (EOG Team)
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir ↗VulnCheck XDB
initial-access
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write
60RIESGO
abrir ↗GitHub PoC★ 1
Multiple vulnerabilities in the vSphere Client (HTML5) were privately reported to VMware. Updates and workarounds are available to address these vulnerabilities in affected VMware products.
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir ↗GitHub PoC
ykg88/OHTS_IE6052-CVE-2020-17087
Windows Kernel Local Elevation of Privilege Vulnerability
71RIESGO
abrir ↗Metasploit300
Squid Proxy Range Header DoS
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a
40RIESGO
abrir ↗Metasploit300
Squid Proxy Range Header DoS
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.3.5 - 'mod_copy' Remote Command Execution (2)
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir ↗GitHub PoC
POC-CVE-2020-7961-Token-iterate
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated)
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access
35RIESGO
abrir ↗Exploit-DB
Codiad 2.8.4 - Remote Code Execution (Authenticated) (3)
Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.
28RIESGO
abrir ↗VulnCheck XDB
infoleak
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, previe
43RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir ↗GitHub PoC
DarkFlameMaster-bit/CVE-2018-8174_EXP
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir ↗Metasploit600
VMware vCenter Server Virtual SAN Health Check Plugin RCE
The vSphere Client (HTML5) contains a remote code execution vulnerability due to lack of input validation in the Virtual
100RIESGO
abrir ↗VulnCheck XDB
initial-access
An argument injection vulnerability in the Dragonfly gem before 1.4.0 for Ruby allows remote attackers to read and write
60RIESGO
abrir ↗VulnCheck XDB
initial-access
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG
53RIESGO
abrir ↗GitHub PoC
qianniaoge/CVE-2020-14882_Exploit_Gui
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin ReDi Restaurant Reservation 21.0307 - 'Comment' Stored Cross-Site Scripting (XSS)
ReDi Restaurant Reservations < 21.0426 - Unauthenticated Stored Cross-Site Scripting (XSS)
23RIESGO
abrir ↗GitHub PoC
Exploit CVE-2017-9248 Telerik ReMix from Paul Taylor's script. Exploit Telerik lastest version fixed vuln. ReMix by TinoKa & Shaco JX
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir ↗Metasploit600
ExifTool DjVu ANT Perl injection
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir ↗GitHub PoC
bgsilvait/WIn-CVE-2021-31166
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 4
WordPress XXE vulnerability
WordPress Authenticated XXE attack when installation is running PHP 8
63RIESGO
abrir ↗GitHub PoC
Qualcomm GPU / ARM Mali GPU
Possible use after free due to improper handling of memory mapping of multiple processes simultaneously. in Snapdragon A
71RIESGO
abrir ↗VulnCheck XDB
initial-access
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir ↗GitHub PoC★ 176
漏洞POC、EXP合集,持续更新。Apache Druid-任意文件读取(CVE-2021-36749)、ConfluenceRCE(CVE-2021-26084)、ZeroShell防火墙RCE(CVE-2019-12725)、ApacheSolr任意文件读取、蓝凌OA任意文件读取、phpStudyRCE、ShowDoc任意文件上传、原创先锋后台未授权、Kyan账号密码泄露、TerraMasterTos任意文件读取、TamronOS-IPTV系统RCE、Wayos防火墙账号密码泄露
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗VulnCheck XDB
infoleak
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir ↗VulnCheck XDB
initial-access
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.