Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
Exploit-DB
Bravo Tejari Web Portal - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal al
23RIESGO
abrir ↗Exploit-DB
Softros Network Time System Server 2.3.4 - Denial of Service
NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service
35RIESGO
abrir ↗Exploit-DB
ActivePDF Toolkit < 8.1.0.19023 - Multiple Memory Corruptions
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out
28RIESGO
abrir ↗Exploit-DB
Suricata < 4.0.4 - IDS Detection Bypass
Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious se
28RIESGO
abrir ↗Exploit-DB
Memcached 1.5.5 - 'Memcrashed' Insufficient Control Network Message Volume Denial of Service (1)
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RIESGO
abrir ↗GitHub PoC★ 2
Tries to exploit a WordPress vulnerability (CVE-2018-6389) which can be used to cause a Denial of Service.
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC★ 131
Improved DOS exploit for wordpress websites (CVE-2018-6389)
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗Metasploit600
ClipBucket beats_uploader Unauthenticated Arbitrary File Upload
An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
uWSGI < 2.0.17 - Directory Traversal
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversa
50RIESGO
abrir ↗Exploit-DB
DualDesk 20 - 'Proxy.exe' Denial of Service
Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500.
35RIESGO
abrir ↗Exploit-DB
antMan < 0.9.1a - Authentication Bypass
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and
35RIESGO
abrir ↗Exploit-DB
TestLink Open Source Test Management < 1.9.16 - Remote Code Execution
install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging c
23RIESGO
abrir ↗Exploit-DB
SEGGER embOS/IP FTP Server 3.22 - Denial of Service
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in
23RIESGO
abrir ↗GitHub PoC★ 8
Joomla - Component Google Map Landkarten <= 4.2.3 - SQL Injection
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a l
28RIESGO
abrir ↗Exploit-DB
D-Link DIR-600M Wireless - Cross-Site Scripting
Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows Kernel (7 x86) - Local Privilege Escalation (MS16-039)
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
76RIESGO
abrir ↗GitHub PoC★ 4
Source code and configuration files related to our article in MISC96
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir ↗GitHub PoC★ 1
cve-2017-10271
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir ↗GitHub PoC
Cisco iOS SNMP Overflow Exploit Toolkit (CVE-2017-6736)
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RIESGO
abrir ↗GitHub PoC★ 2
CVE-2018-6389 WordPress Core - 'load-scripts.php' Denial of Service <= 4.9.4
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC
alessiogilardi/PoC---CVE-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC★ 1
This is a sort of Java porting of the Python exploit at: https://www.exploit-db.com/exploits/41570/.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC★ 82
A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS 11.2.5 / watchOS 4.2.2 / tvOS 11.2.5 - 'bluetoothd' Memory Corruption
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RIESGO
abrir ↗VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Routers2 2.24 - Cross-Site Scripting
A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph
23RIESGO
abrir ↗Exploit-DB
School Management Script 3.0.4 - Authentication Bypass
SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Asterisk chan_pjsip 15.2.0 - 'SUBSCRIBE' Stack Corruption
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce
35RIESGO
abrir ↗Exploit-DB
CMS Made Simple 2.1.6 - Remote Code Execution
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.