Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.207exploits catalogados
36.419CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.464Referência 23.022GitHub PoC 15.023VulnCheck XDB 8846Nuclei 4361Metasploit 3491✓ solo verificadosrecientespopularesriesgo
79.203 exploits
GitHub PoC
N0b1e6/CVE-2018-1335-Python3
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir ↗Exploit-DB
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir ↗GitHub PoC★ 336
CVE-2020-0683 - Windows MSI “Installer service” Elevation of Privilege
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RIESGO
abrir ↗Exploit-DB
WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scripting
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iOS/macOS - Out-of-Bounds Timestamp Write in IOAccelCommandQueue2::processSegmentKernelCommand()
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3
76RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link Devices - Unauthenticated Remote Command Execution in ssdpcgi (Metasploit)
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ricoh Driver - Privilege Escalation (Metasploit)
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RIESGO
abrir ↗Exploit-DB
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade
23RIESGO
abrir ↗Metasploit600
Unraid 6.8.0 Auth Bypass PHP Code Execution
Unraid through 6.8.0 allows Remote Code Execution.
100RIESGO
abrir ↗Exploit-DB
Dota 2 7.23f - Denial of Service (PoC)
schemasystem.dll in Valve Dota 2 before 7.23f allows remote attackers to achieve code execution or denial of service by
23RIESGO
abrir ↗GitHub PoC★ 3
VanillaForum 2.6.3 allows stored XSS.
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RIESGO
abrir ↗Metasploit600
Unraid 6.8.0 Auth Bypass PHP Code Execution
Unraid 6.8.0 allows authentication bypass.
100RIESGO
abrir ↗GitHub PoC★ 7
Containerized and deployable use of the CVE-2019-14287 vuln. View README.md for more.
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir ↗GitHub PoC★ 1
Exhaust WordPress <V5.0.1 resources using long passwords (CVE-2014-9016)
The password hashing API in Drupal 7.x before 7.34 and the Secure Password Hashes (aka phpass) module 6.x-2.x before 6.x
60RIESGO
abrir ↗GitHub PoC
Adapted CVE-2015-8562 payload
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Windscribe - WindscribeService Named Pipe Privilege Escalation (Metasploit)
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
38RIESGO
abrir ↗Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RIESGO
abrir ↗Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir ↗GitHub PoC★ 59
A functional exploit for CVE-2019-18634, a BSS overflow in sudo's pwfeedback feature that allows for for privesc
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir ↗GitHub PoC★ 237
Proof of Concept for CVE-2019-18634
In Sudo before 1.8.26, if pwfeedback is enabled in /etc/sudoers, users can trigger a stack-based buffer overflow in the
28RIESGO
abrir ↗Exploit-DB
EyesOfNetwork 5.3 - Remote Code Execution
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RIESGO
abrir ↗Metasploit600
Horde CSV import arbitrary PHP code execution
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu
60RIESGO
abrir ↗Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RIESGO
abrir ↗Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RIESGO
abrir ↗Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RIESGO
abrir ↗Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL
40RIESGO
abrir ↗Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.