Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.858exploits catalogados
36.825CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.346GitHub PoC 15.209VulnCheck XDB 8944Nuclei 4383Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.697 exploits
Metasploit300
Microsoft Windows ALPC Task Scheduler Local Privilege Elevation
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Jetdirect - Path Traversal Arbitrary Code Execution (Metasploit)
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RIESGO
abrir ↗Exploit-DB
Gleez CMS 1.2.0 - Cross-Site Request Forgery (Add Admin)
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Plainview Activity Monitor 20161228 - (Authenticated) Command Injection
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Electron WebPreferences - Remote Code Execution
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindow
28RIESGO
abrir ↗GitHub PoC★ 21
Proof of Concept for CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Exploit-DB
RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin)
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Responsive FileManager < 9.13.4 - Directory Traversal
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc
23RIESGO
abrir ↗Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1)
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Exploit-DB
ManageEngine ADManager Plus 6.5.7 - Cross-Site Scripting
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
23RIESGO
abrir ↗Metasploit600
Wordpress Plainview Activity Monitor RCE
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Exploit-DB
ManageEngine ADManager Plus 6.5.7 - HTML Injection
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
23RIESGO
abrir ↗GitHub PoC★ 3
moayadalmalat/CVE-2017-12636
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RIESGO
abrir ↗GitHub PoC★ 303
An exploit for Apache Struts CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗GitHub PoC★ 4
Environment for CVE-2018-11776 / S2-057 (Apache Struts 2)
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗GitHub PoC★ 12
Vulnerable docker container for CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (2)
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗GitHub PoC★ 10
CVE-2018-11776(S2-057) EXPLOIT CODE
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗GitHub PoC★ 123
Working Python test and PoC for CVE-2018-11776, includes Docker lab
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗VulnCheck XDB
client-side
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
93RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗GitHub PoC★ 21
Simple poc of CVE-2018-8414 Windows Package Setting RCE Vulnerability
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
93RIESGO
abrir ↗GitHub PoC★ 15
Creating a vulnerable environment and the PoC
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.