Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
22.786 exploits
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir ↗Exploit-DB
Canon PrintMe EFI - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB
WebKitGTK+ < 2.21.3 - 'WebKitFaviconDatabase' Denial of Service (Metasploit)
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RIESGO
abrir ↗Exploit-DB
Schools Alert Management Script - 'get_sec.php' SQL Injection
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
23RIESGO
abrir ↗Exploit-DB
Schools Alert Management Script - SQL Injection
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph
23RIESGO
abrir ↗Exploit-DB
Schools Alert Management Script - Arbitrary File Read
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin Pie Register < 3.0.9 - Blind SQL Injection
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute ar
23RIESGO
abrir ↗Exploit-DB
Schools Alert Management Script - Arbitrary File Deletion
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p
28RIESGO
abrir ↗Exploit-DB
WebKit - WebAssembly Compilation Info Leak
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RIESGO
abrir ↗Exploit-DB
WebRTC - VP9 Missing Frame Processing Out-of-Bounds Memory Access
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially per
23RIESGO
abrir ↗Exploit-DB
Google Chrome - Integer Overflow when Processing WebAssembly Locals
An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker t
23RIESGO
abrir ↗Exploit-DB
XiongMai uc-httpd 1.0.0 - Buffer Overflow
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
50RIESGO
abrir ↗Exploit-DB
TrendMicro OfficeScan XG 11.0 - Change Prevention Bypass
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or
23RIESGO
abrir ↗Exploit-DB
Splunk < 7.0.1 - Information Disclosure
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
60RIESGO
abrir ↗Exploit-DB
WebKit - Use-After-Free when Resuming Generator
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
23RIESGO
abrir ↗Exploit-DB
WebRTC - VP9 Frame Processing Out-of-Bounds Memory Access
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to pot
23RIESGO
abrir ↗Exploit-DB
Monstra CMS < 3.0.4 - Cross-Site Scripting (1)
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RIESGO
abrir ↗Exploit-DB
PHP 7.2.2 - 'php_stream_url_wrap_http_ex' Buffer Overflow
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer
45RIESGO
abrir ↗Exploit-DB
Apple macOS Kernel - Use-After-Free Due to Lack of Locking in nvidia GeForce Driver
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Grap
23RIESGO
abrir ↗Exploit-DB
XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB
Apple macOS/iOS Kernel - Heap Overflow Due to Lack of Lower Size Check in getvolattrlist
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RIESGO
abrir ↗Exploit-DB
WebKit - not_number defineProperties UAF (Metasploit)
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir ↗Exploit-DB
WebKit - not_number defineProperties UAF (Metasploit)
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RIESGO
abrir ↗Exploit-DB
Linux Kernel < 4.16.11 - 'ext4_read_inline_data()' Memory Corruption
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untruste
28RIESGO
abrir ↗Exploit-DB
Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email)
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.