Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
Exploit-DB✓ VexDay Proof
Joomla! Component Acymailing Starter 5.9.5 - CSV Macro Injection
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing exte
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component AcySMS 3.5.0 - CSV Macro Injection
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extensio
23RIESGO
abrir ↗Exploit-DB
Homematic CCU2 2.29.23 - Remote Command Execution
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers
35RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 114
CVE-2018-7600 Drupal RCE
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗GitHub PoC★ 354
💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Exploit-DB
MiniCMS 1.10 - Cross-Site Request Forgery
There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
23RIESGO
abrir ↗Exploit-DB
Open-AuditIT Professional 2.1 - Cross-Site Request Forgery
Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the cre
23RIESGO
abrir ↗Exploit-DB
Homematic CCU2 2.29.23 - Arbitrary File Write
Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic C
35RIESGO
abrir ↗Exploit-DB
D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router - Authentication Bypass
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Versi
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin WP Security Audit Log 3.1.1 - Sensitive Information Disclosure
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-securit
43RIESGO
abrir ↗Exploit-DB
Vtiger CRM 6.3.0 - (Authenticated) Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
43RIESGO
abrir ↗Exploit-DB
Systematic SitAware - NVG Denial of Service
Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG
23RIESGO
abrir ↗GitHub PoC
lucad93/CVE-2018-3810
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RIESGO
abrir ↗Exploit-DB
Cisco Smart Install - Crash (PoC)
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GitStack - Unsanitized Argument Remote Code Execution (Metasploit)
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Exodus Wallet (ElectronJS Framework) - Remote Code Execution (Metasploit)
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Fields - SQLi Remote Code Execution (Metasploit)
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗Exploit-DB
TwonkyMedia Server 7.0.11-8.5 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Exploit-DB
TwonkyMedia Server 7.0.11-8.5 - Directory Traversal
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Remote Assistance - XML External Entity Injection
Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Window
33RIESGO
abrir ↗Metasploit600
Drupal Drupalgeddon 2 Forms API Property Injection
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Exploit-DB
Open-AuditIT Professional 2.1 - Cross-Site Scripting
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
23RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir ↗GitHub PoC★ 5
CVE-2017-14322 Interspire Email Marketer (emailmarketer) Exploit
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior
35RIESGO
abrir ↗Exploit-DB
DLINK DCS-5020L - Remote Code Execution (PoC)
On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DC
28RIESGO
abrir ↗Exploit-DB
Laravel Log Viewer < 0.13.0 - Local File Download
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easi
28RIESGO
abrir ↗Exploit-DB
Microsoft Windows Manager (7 x86) - Menu Management Component UAF Privilege Elevation
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.