Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
Exploit-DB✓ VexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir ↗Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applicat
28RIESGO
abrir ↗Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir ↗Exploit-DB
JioFi 4G M2S 1.0.2 - Denial of Service (PoC)
JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS paylo
23RIESGO
abrir ↗Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability
43RIESGO
abrir ↗GitHub PoC★ 259
PoC for CVE-2018-15133 (Laravel unserialize vulnerability)
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir ↗Exploit-DB
cgit 1.2.1 - Directory Traversal (Metasploit)
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned
60RIESGO
abrir ↗VulnCheck XDB
initial-access
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit)
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir ↗Exploit-DB
Cloudme 1.9 - Buffer Overflow (DEP) (Metasploit)
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir ↗Exploit-DB
Oracle Glassfish OSE 4.1 - Path Traversal (Metasploit)
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir ↗GitHub PoC
kaisaryousuf/CVE-2018-8208
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RIESGO
abrir ↗Exploit-DB
PostgreSQL 9.4-0.5.3 - Privilege Escalation
local privilege escalation in SUSE postgresql init script
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Android - Directory Traversal over USB via Injection in blkid Output
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerabili
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Weblogic Server - Deserialization Remote Code Execution (Metasploit)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗Metasploit300
Pimcore Gather Credentials via SQL Injection
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RIESGO
abrir ↗Exploit-DB
Zimbra 8.6.0_GA_1153 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrar
23RIESGO
abrir ↗Exploit-DB
MyBB Thank You/Like Plugin 3.0.0 - Cross-Site Scripting
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa
23RIESGO
abrir ↗Exploit-DB
reSIProcate 1.10.2 - Heap Overflow
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows rem
28RIESGO
abrir ↗Exploit-DB
Linux Kernel 4.14.7 (Ubuntu 16.04 / CentOS 7) - (KASLR & SMEP Bypass) Arbitrary File Read
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly
23RIESGO
abrir ↗Exploit-DB
osTicket 1.10.1 - Arbitrary File Upload
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly v
28RIESGO
abrir ↗GitHub PoC★ 119
Implements the POP/MOV SS (CVE-2018-8897) vulnerability by leveraging SYSCALL to perform a local privilege escalation (LPE).
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir ↗VulnCheck XDB
client-side
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RIESGO
abrir ↗GitHub PoC★ 178
Exploit for CVE-2018-4233, a WebKit JIT optimization bug used during Pwn2Own 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RIESGO
abrir ↗Metasploit600
PHP Laravel Framework token Unserialize Remote Command Execution
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir ↗Metasploit600
PHP Laravel Framework token Unserialize Remote Command Execution
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RIESGO
abrir ↗Exploit-DB
Open-AudIT Community 2.2.6 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inj
35RIESGO
abrir ↗Exploit-DB
Subrion CMS 4.2.1 - Cross-Site Scripting
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for exam
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.