Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
Exploit-DB
WordPress Plugin File Upload 4.3.2 - Stored Cross-Site Scripting
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
23RIESGO
abrir ↗Exploit-DB
Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection A
50RIESGO
abrir ↗GitHub PoC★ 14
Fixed No Virus Manual Automatic Loader exe no zip because zip picks up the anti virus detector.
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir ↗Exploit-DB
Cobub Razor 0.7.2 - Add New Superuser Account
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/inst
28RIESGO
abrir ↗Exploit-DB
WolfCMS 0.8.3.1 - Open Redirection
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attack
23RIESGO
abrir ↗Exploit-DB
WolfCMS 0.8.3.1 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Background Takeover < 4.1.4 - Directory Traversal
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - WebAssembly Parsing Does not Correctly Check Section Order
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RIESGO
abrir ↗Metasploit600
H2 Web Interface Create Alias RCE
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can
30RIESGO
abrir ↗Exploit-DB
iScripts SonicBB 1.0 - Reflected Cross-Site Scripting (PoC)
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
23RIESGO
abrir ↗Exploit-DB
Yahei PHP Prober 0.4.7 - Cross-Site Scripting
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
23RIESGO
abrir ↗Exploit-DB
CyberArk Password Vault Web Access < 9.9.5 / < 9.10 / 10.1 - Remote Code Execution
The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute
28RIESGO
abrir ↗Exploit-DB
CyberArk Password Vault < 9.7 / < 10 - Memory Disclosure
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RIESGO
abrir ↗GitHub PoC★ 5
CVE-2017-8570生成脚本(CVE-2017-0199另一种利用方式)
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir ↗Exploit-DB
GNU Beep 1.3 - 'HoleyBeep' Local Privilege Escalation
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cobub Razor 0.7.2 - Cross-Site Request Forgery
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/chann
23RIESGO
abrir ↗Exploit-DB
DotNetNuke DNNarticle Module 11 - Directory Traversal
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and conseque
35RIESGO
abrir ↗GitHub PoC★ 3
Android Blueborne RCE CVE-2017-0781
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir ↗Exploit-DB
Adobe Flash < 28.0.0.161 - Use-After-Free
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir ↗Exploit-DB
FiberHome VDSL2 Modem HG 150-UB - Authentication Bypass
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
28RIESGO
abrir ↗Exploit-DB
Sophos Endpoint Protection Control Panel 10.7 - Weak Password Encryption
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Vir
23RIESGO
abrir ↗GitHub PoC★ 2
Android Blueborne RCE CVE-2017-0781
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir ↗Exploit-DB
LineageOS 14.1 Blueborne - Remote Code Execution
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir ↗Exploit-DB
Sophos Endpoint Protection 10.7 - Tamper-Protection Bypass
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKE
23RIESGO
abrir ↗Exploit-DB
YzmCMS 3.6 - Cross-Site Scripting
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
38RIESGO
abrir ↗Exploit-DB
Joomla! Component JS Jobs 1.2.0 - Cross-Site Scripting
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.
23RIESGO
abrir ↗Exploit-DB
Z-Blog 1.5.1.1740 - Full Path Disclosure
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.ph
23RIESGO
abrir ↗Exploit-DB
GetSimple CMS 3.3.13 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows rem
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Activity Log 2.4.0 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.