Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
22.786 exploits
Exploit-DB
FTPShell Client 6.7 - Buffer Overflow
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RIESGO
abrir ↗Exploit-DB
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RIESGO
abrir ↗Exploit-DB
2345 Security Guard 3.7 - '2345NetFirewall.sys' Denial of Service
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)
23RIESGO
abrir ↗Exploit-DB
Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir ↗Exploit-DB
GNU wget - Cookie Injection
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequen
28RIESGO
abrir ↗Exploit-DB
CSP MySQL User Manager 2.3.1 - Authentication Bypass
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a
23RIESGO
abrir ↗Exploit-DB
DeviceLock Plug and Play Auditor 5.72 - Unicode Buffer Overflow (SEH)
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RIESGO
abrir ↗Exploit-DB
IceWarp Mail Server < 11.1.1 - Directory Traversal
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin
23RIESGO
abrir ↗Exploit-DB
Google Chrome V8 - Object Allocation Size Integer Overflow
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RIESGO
abrir ↗Exploit-DB
Microsoft Windows WMI - Recieve Notification Exploit (Metasploit)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir ↗Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir ↗Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images
100RIESGO
abrir ↗Exploit-DB
JasperReports - (Authenticated) File Read
TIBCO JasperReports Server Information Disclosure Vulnerability
83RIESGO
abrir ↗Exploit-DB
Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to r
23RIESGO
abrir ↗Exploit-DB
Exim < 4.90.1 - 'base64d' Remote Code Execution
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir ↗Exploit-DB
LibreOffice/Open Office - '.odt' Information Disclosure
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RIESGO
abrir ↗Exploit-DB
TBK DVR4104 / DVR4216 - Credentials Leak
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗Exploit-DB
Norton Core Secure WiFi Router - 'BLE' Command Injection (PoC)
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RIESGO
abrir ↗Exploit-DB
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Responsive Cookie Consent 1.7 / 1.6 / 1.5 - (Authenticated) Persistent Cross-Site Scripting
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
23RIESGO
abrir ↗Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RIESGO
abrir ↗Exploit-DB
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RIESGO
abrir ↗Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RIESGO
abrir ↗Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RIESGO
abrir ↗Exploit-DB
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin Form Maker 1.12.20 - CSV Injection
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
23RIESGO
abrir ↗Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RIESGO
abrir ↗Exploit-DB
Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools"
23RIESGO
abrir ↗Exploit-DB
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.