Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tuleap 9.17.99.189 - Blind SQL Injection
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 a
23RIESGO
abrir ↗Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers
23RIESGO
abrir ↗Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e
28RIESGO
abrir ↗Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1
23RIESGO
abrir ↗Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mai
23RIESGO
abrir ↗Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbit
23RIESGO
abrir ↗Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitr
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir ↗GitHub PoC★ 37
PoC code for CVE-2017-13253
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. Thi
23RIESGO
abrir ↗GitHub PoC★ 1
PoC for SpringBreak (CVE-2017-8046)
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir ↗Exploit-DB
DEWESoft X3 SP1 (x64) - Remote Command Execution
RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP
35RIESGO
abrir ↗VulnCheck XDB
initial-access
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir ↗Exploit-DB
TextPattern 4.6.2 - 'qty' SQL Injection
An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on
23RIESGO
abrir ↗Exploit-DB
ManageEngine Applications Manager 13.5 - Remote Code Execution (Metasploit)
A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The pu
60RIESGO
abrir ↗GitHub PoC★ 95
Exploitation Tool for CVE-2017-3066 targeting Adobe Coldfusion 11/12
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advantech WebAccess < 8.3 - Directory Traversal / Remote Code Execution
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within th
35RIESGO
abrir ↗GitHub PoC
fibonascii/CVE-2004-0558
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of s
28RIESGO
abrir ↗Metasploit300
Flexense HTTP Server Denial Of Service
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RIESGO
abrir ↗Exploit-DB
Bacula-Web < 8.0.0-rc2 - SQL Injection
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access
28RIESGO
abrir ↗GitHub PoC★ 17
This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir ↗Exploit-DB
WebLog Expert Enterprise 9.4 - Denial of Service
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to
35RIESGO
abrir ↗Exploit-DB
WebLog Expert Enterprise 9.4 - Authentication Bypass
\ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUIL
23RIESGO
abrir ↗GitHub PoC★ 2
Exploit iOS 11.2.x by ZIMPERIUM and semi-completed by me. Sandbox escapes on CVE-2018-4087.
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RIESGO
abrir ↗GitHub PoC★ 14
WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk!
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir ↗Exploit-DB
Memcached 1.5.5 - 'Memcrashed ' Insufficient Control of Network Message Volume Denial of Service With Shodan API
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RIESGO
abrir ↗Metasploit300
HTTP SickRage Password Leak
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RIESGO
abrir ↗Metasploit600
ManageEngine Applications Manager Remote Code Execution
A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The pu
60RIESGO
abrir ↗Exploit-DB
antMan 0.9.0c - Authentication Bypass
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.