Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8883Nuclei 4365Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.386 exploits
Exploit-DB
BlogEngine 3.3 - XML External Entity Injection
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
28RIESGO
abrir ↗GitHub PoC★ 678
ES File Explorer Open Port Vulnerability - CVE-2019-6447
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RIESGO
abrir ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RIESGO
abrir ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/
23RIESGO
abrir ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RIESGO
abrir ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RIESGO
abrir ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/
100RIESGO
abrir ↗Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir ↗Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
60RIESGO
abrir ↗Exploit-DB
LayerBB 1.1.1 - Persistent Cross-Site Scripting
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RIESGO
abrir ↗GitHub PoC
poc for 0263
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RIESGO
abrir ↗Exploit-DB
MyBB OUGC Awards Plugin 1.8.3 - Persistent Cross-Site Scripting
The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards pag
23RIESGO
abrir ↗Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
28RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗GitHub PoC★ 12
漏洞利用工具
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Scripting
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RIESGO
abrir ↗Exploit-DB
KioWare Server Version 4.9.6 - Weak Folder Permissions Privilege Escalation
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any
23RIESGO
abrir ↗Exploit-DB
Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ
28RIESGO
abrir ↗Exploit-DB
Huawei E5330 21.210.09.00.158 - Cross-Site Request Forgery (Send SMS)
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13S
23RIESGO
abrir ↗GitHub PoC
cve-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC
CVE-2009-1324 - ASX to MP3 Converter Local Buffer Overflow. Tested on Windows XP Professional SP3
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RIESGO
abrir ↗GitHub PoC★ 1
cve-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗GitHub PoC
CVE-2018-6389 PoC node js multisite with proxy
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC
cve-2015-1427
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir ↗GitHub PoC
cve-2015-8103
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RIESGO
abrir ↗GitHub PoC
cve-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC
cve-2015-5602
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RIESGO
abrir ↗GitHub PoC
cve-2015-3306
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir ↗GitHub PoC
cve-2016-6515
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RIESGO
abrir ↗GitHub PoC
cve-2017-7494
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.