Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
Exploit-DB
MyBB New Threads Plugin 1.1 - Cross-Site Scripting
The New Threads plugin before 1.2 for MyBB has XSS.
35RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RIESGO
abrir ↗Exploit-DB
Open-AudIT Community 2.1.1 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows
23RIESGO
abrir ↗Metasploit300
Eaton Xpert Meter SSH Private Key Exposure Scanner
Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different cus
30RIESGO
abrir ↗GitHub PoC
likekabin/CVE-2018-4121
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RIESGO
abrir ↗GitHub PoC
likekabin/ShareDoc_cve-2015-5477
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nanopool Claymore Dual Miner - APIs Remote Code Execution (Metasploit)
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux (Ubuntu) - Other Users coredumps Can Be Read via setgid Directory and killpriv Bypass
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RIESGO
abrir ↗Exploit-DB
PrestaShop < 1.6.1.19 - 'BlowFish ECD' Privilege Escalation
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RIESGO
abrir ↗Exploit-DB
VelotiSmart WiFi B-380 Camera - Directory Traversal
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RIESGO
abrir ↗GitHub PoC★ 49
Collection of exploits/POC for PrestaShop cookie vulnerabilities (CVE-2018-13784)
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RIESGO
abrir ↗Exploit-DB
PrestaShop < 1.6.1.19 - 'AES CBC' Privilege Escalation
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin - (Authenticated) Remote Code Execution (Metasploit)
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr
68RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache CouchDB - Arbitrary Command Execution (Metasploit)
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir ↗Exploit-DB
Cela Link CLR-M20 2.7.1.6 - Arbitrary File Upload
CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml)
28RIESGO
abrir ↗Exploit-DB
Grundig Smart Inter@ctive 3.0 - Cross-Site Request Forgery
Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - POP/MOV SS Local Privilege Elevation (Metasploit)
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir ↗Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RIESGO
abrir ↗VulnCheck XDB
local
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir ↗Exploit-DB
Zeta Producer Desktop CMS 14.2.0 - Remote Code Execution / Local File Disclosure
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.