Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Exploit-DB
AMD Plays.tv 1.27.5.0 - 'plays_service.exe' Arbitrary File Execution
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RIESGO
abrir ↗GitHub PoC★ 7
Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 4
Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 3
Tool to check for CVE-2018-7600 vulnerability on several URLS
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Metasploit600
Pi-Hole Whitelist OS Command Execution
Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution
63RIESGO
abrir ↗GitHub PoC★ 41
CVE-2018-6546-Exploit
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RIESGO
abrir ↗GitHub PoC★ 4
PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2).
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 7
Drupal 0day Remote PHP Code Execution (Perl)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 5
MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 3
CVE-2018-7600 (Drupal)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir ↗Exploit-DB
MikroTik 6.41.4 - FTP daemon Denial of Service (PoC)
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU a
28RIESGO
abrir ↗GitHub PoC★ 10
Environment for CVE-2018-1273 (Spring Data Commons)
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir ↗Exploit-DB
Microsoft Credential Security Support Provider - Remote Code Execution
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 603
Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Exploit-DB
Joomla! Convert Forms version 2.0.3 - Formula Injection (CSV Injection)
The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that
23RIESGO
abrir ↗GitHub PoC
Example exploit for CVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗Exploit-DB
DVD X Player Standard 5.5.3.9 - Buffer Overflow
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RIESGO
abrir ↗Exploit-DB
iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Activity Log 2.4.0 - Stored Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RIESGO
abrir ↗GitHub PoC★ 14
Fixed No Virus Manual Automatic Loader exe no zip because zip picks up the anti virus detector.
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir ↗Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery (Add Admin)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin File Upload 4.3.2 - Stored Cross-Site Scripting
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.