Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
GitHub PoC★ 11
Al1ex/CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chi
48RIESGO
abrir ↗GitHub PoC★ 6
POC to test/exploit drupal vulnerability SA-CORE-2018-004 / CVE-2018-7602
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir ↗Exploit-DB
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RIESGO
abrir ↗Metasploit600
GitList v0.6.0 Argument Injection Vulnerability
klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in
40RIESGO
abrir ↗Exploit-DB
October CMS User Plugin 1.4.5 - Persistent Cross-Site Scripting
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam
23RIESGO
abrir ↗Exploit-DB
Frog CMS 0.9.5 - Persistent Cross-Site Scripting
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
23RIESGO
abrir ↗Exploit-DB
MyBB Threads to Link Plugin 1.3 - Cross-Site Scripting
An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the opt
23RIESGO
abrir ↗Exploit-DB
Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RIESGO
abrir ↗GitHub PoC★ 13
CVE-2017-16995(Ubuntu本地提权漏洞)
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir ↗GitHub PoC
CVE-2018-9160
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RIESGO
abrir ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - Local File Inclusion
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - (Authenticated) Cross-Site Scripting
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged u
23RIESGO
abrir ↗VulnCheck XDB
infoleak
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before
60RIESGO
abrir ↗Metasploit600
Apache Tika Header Command Injection
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir ↗Exploit-DB
Shopy Point of Sale 1.0 - CSV Injection
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to
23RIESGO
abrir ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - CSV Injection
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RIESGO
abrir ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - 'award_id' SQL Injection
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RIESGO
abrir ↗Exploit-DB
Blog Master Pro 1.0 - CSV Injection
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level pri
23RIESGO
abrir ↗Exploit-DB
Easy File Sharing Web Server 7.2 - 'UserID' Remote Buffer Overflow (DEP Bypass)
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir ↗GitHub PoC★ 2
Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
23RIESGO
abrir ↗Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that a
23RIESGO
abrir ↗Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any
28RIESGO
abrir ↗Exploit-DB
Monstra CMS 3.0.4 - Arbitrary Folder Deletion
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uplo
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.