Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
Exploit-DB
Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code Execution
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir ↗Exploit-DB
Airties AIR5444TT - Cross-Site Scripting
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
23RIESGO
abrir ↗Exploit-DB
PolarisOffice 2017 8 - Remote Code Execution
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in
28RIESGO
abrir ↗GitHub PoC★ 1
lonehand/Oracle-WebLogic-CVE-2017-10271-master
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir ↗Exploit-DB
ADB Broadband Gateways / Routers - Privilege Escalation
All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerabilit
23RIESGO
abrir ↗Exploit-DB
ADB Broadband Gateways / Routers - Local Root Jailbreak
All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerabilit
23RIESGO
abrir ↗Exploit-DB
ADB Broadband Gateways / Routers - Authorization Bypass
All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerabili
35RIESGO
abrir ↗Exploit-DB
ShopNx - Arbitrary File Upload
An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious
23RIESGO
abrir ↗Exploit-DB
Online Trade - Information Disclosure
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CMS Made Simple 2.2.5 - (Authenticated) Remote Code Execution
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows a
50RIESGO
abrir ↗Metasploit600
CMS Made Simple Authenticated RCE via File Upload/Copy
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Boxoft WAV to MP3 Converter 1.1 - Buffer Overflow (Metasploit)
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RIESGO
abrir ↗Exploit-DB
ntop-ng < 3.4.180617 - Authentication Bypass
An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seede
28RIESGO
abrir ↗Exploit-DB
Delta Industrial Automation COMMGR 1.08 - Stack Buffer Overflow (PoC)
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPS
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RIESGO
abrir ↗Metasploit300
Delta Electronics Delta Industrial Automation COMMGR 1.08 Stack Buffer Overflow
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPS
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FTPShell Client 6.70 (Enterprise Edition) - Stack Buffer Overflow (Metasploit)
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RIESGO
abrir ↗GitHub PoC★ 3
likekabin/CVE-2018-2628
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware NSX SD-WAN Edge < 3.1.2 - Command Injection
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RIESGO
abrir ↗VulnCheck XDB
infoleak
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗GitHub PoC
Aruthw/CVE-2014-6271
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HongCMS 3.0.0 - (Authenticated) SQL Injection
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via a
23RIESGO
abrir ↗GitHub PoC
qy1202/https-github.com-Ridter-CVE-2017-11882-
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗Exploit-DB
Cisco Adaptive Security Appliance - Path Traversal
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir ↗Exploit-DB
BEESCMS 4.0 - Cross-Site Request Forgery (Add Admin)
In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
23RIESGO
abrir ↗VulnCheck XDB
denial-of-service
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.