Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.095 exploits
Metasploit600
pfSense authenticated group member RCE
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_
30RIESGO
abrir ↗GitHub PoC★ 4
Unrestricted file upload vulnerability - Web Viewer 1.0.0.193 on Samsung SRN-1670D
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_u
50RIESGO
abrir ↗Exploit-DB
Avaya IP Office (IPO) < 10.1 - 'SoftConsole' Remote Buffer Overflow (SEH)
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary co
23RIESGO
abrir ↗Exploit-DB
Avaya IP Office (IPO) < 10.1 - ActiveX Buffer Overflow
Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows r
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Userpro < 4.9.17.1 - Authentication Bypass
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers
28RIESGO
abrir ↗Exploit-DB
GraphicsMagick - Memory Disclosure / Heap Overflow
GraphicsMagick 1.3.26 is vulnerable to a heap-based buffer overflow vulnerability found in the "Display visual image dir
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
tnftp - 'savefile' Arbitrary Command Execution (Metasploit)
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 thro
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch WS_FTP Professional < 12.6.0.3 - Local Buffer Overflow (SEH)
Ipswitch WS_FTP Professional before 12.6.0.3 has buffer overflows in the local search field and the backup locations fie
23RIESGO
abrir ↗GitHub PoC★ 5
Exploit for the linux kernel vulnerability CVE-2017-5123
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir ↗GitHub PoC★ 2
RTF de-obfuscator for CVE-2017-0199 documents to find URLs statically.
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir ↗Exploit-DB
GraphicsMagick - Memory Disclosure / Heap Overflow
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function
28RIESGO
abrir ↗Exploit-DB
Logitech Media Server 7.9.0 - 'Radio URL' Cross-Site Scripting
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality.
23RIESGO
abrir ↗Exploit-DB
Logitech Media Server 7.9.0 - 'favorites' Cross-Site Scripting
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. T
23RIESGO
abrir ↗Metasploit300
Brother Debut http Denial Of Service
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST requ
50RIESGO
abrir ↗Metasploit400
Advantech WebAccess Webvrpcs Service Opcode 80061 Stack Buffer Overflow
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati
43RIESGO
abrir ↗Exploit-DB
Debut Embedded HTTPd 1.20 - Denial of Service
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST requ
50RIESGO
abrir ↗Exploit-DB
Cisco UCS Platform Emulator 3.1(2ePE1) - Remote Code Execution
A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewal
45RIESGO
abrir ↗Exploit-DB
OctoberCMS 1.0.426 (Build 426) - Cross-Site Request Forgery
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for po
23RIESGO
abrir ↗GitHub PoC★ 3
tomcat-put-cve-2017-12615
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗Exploit-DB
Vir.IT eXplorer Anti-Virus 8.5.39 - 'VIAGLT64.SYS' Local Privilege Escalation
In Vir.IT eXplorer Anti-Virus before 8.5.42, the driver file (VIAGLT64.SYS) contains an Arbitrary Write vulnerability be
23RIESGO
abrir ↗VulnCheck XDB
initial-access
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗Exploit-DB
ZyXEL PK5001Z Modem - Backdoor Account
ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access
28RIESGO
abrir ↗GitHub PoC★ 1
linux kernel exploit
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir ↗Exploit-DB
Php Inventory - Arbitrary File Upload
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
23RIESGO
abrir ↗Exploit-DB
MyBuilder Clone 1.0 - 'subcategory' SQL Injection
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
23RIESGO
abrir ↗GitHub PoC
skyformat99/dnsmasq-2.4.1-fix-CVE-2017-14491
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir ↗Exploit-DB
Zomato Clone Script - 'resid' SQL Injection
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
23RIESGO
abrir ↗Exploit-DB
Online Exam Test Application - 'sort' SQL Injection
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
23RIESGO
abrir ↗Exploit-DB
AROX School ERP PHP Script - 'id' SQL Injection
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
23RIESGO
abrir ↗Exploit-DB
ZeeBuddy 2x - 'groupid' SQL Injection
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-200
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.