Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.095 exploits
GitHub PoC
This is the Apache Struts CVE-2017-5638 struts 2 vulnerability. The same CVE that resulted in the equifax database breach.
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB
iTech Gigs Script 1.21 - SQL Injection
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser pa
23RIESGO
abrir ↗Exploit-DB
CmsLite 1.4 - 'S' SQL Injection
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
23RIESGO
abrir ↗Metasploit600
Xplico Remote Code Execution
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RIESGO
abrir ↗Exploit-DB
PHP Melody 2.6.1 - SQL Injection
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
23RIESGO
abrir ↗GitHub PoC★ 2
This exploit was written to study some concepts, enjoy!
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RIESGO
abrir ↗Exploit-DB
PHPMyFAQ 2.9.8 - Cross-Site Scripting (3)
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.
23RIESGO
abrir ↗Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
23RIESGO
abrir ↗Exploit-DB
HitmanPro 3.7.15 Build 281 - Kernel Pool Overflow
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in
23RIESGO
abrir ↗Exploit-DB
Watchdog Development Anti-Malware / Online Security Pro - NULL Pointer Dereference
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer
23RIESGO
abrir ↗Exploit-DB
Watchdog Development Anti-Malware / Online Security Pro - NULL Pointer Dereference
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer
23RIESGO
abrir ↗Exploit-DB
KeystoneJS 4.0.0-beta.5 - Cross-Site Scripting
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-be
23RIESGO
abrir ↗Exploit-DB
KeystoneJS 4.0.0-beta.5 - CSV Excel Macro Injection
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCS
23RIESGO
abrir ↗Exploit-DB
PHPMailer < 5.2.21 - Local File Disclosure
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML docume
23RIESGO
abrir ↗Exploit-DB
Mura CMS < 6.2 - Server-Side Request Forgery / XML External Entity Injection
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the
23RIESGO
abrir ↗GitHub PoC★ 2
dewankpant/CVE-2017-16567
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. T
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unitrends UEB 9 - http api/storage Remote Root (Metasploit)
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir ↗Exploit-DB
K7 Total Security 15.1.0.305 - Device Driver Arbitrary Memory Read
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unitrends UEB 9 - bpserverd Authentication Bypass Remote Command Execution (Metasploit)
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kaltura < 13.2.0 - Remote Code Execution
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, wh
60RIESGO
abrir ↗Metasploit600
Tuleap 9.6 Second-Order PHP Object Injection
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentEl
50RIESGO
abrir ↗GitHub PoC
Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir ↗Exploit-DB
Linux Kernel 4.14.0-rc4+ - 'waitid()' Local Privilege Escalation
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir ↗Metasploit300
Ayukov NFTP FTP Client Buffer Overflow
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ayukov NFTP FTP Client < 2.0 - Remote Buffer Overflow
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RIESGO
abrir ↗Exploit-DB
ArGoSoft Mini Mail Server 1.0.0.2 - Denial of Service
Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox < 55 - Denial of Service
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example
28RIESGO
abrir ↗GitHub PoC★ 1
Dirty COW (CVE-2016-5195) Testing
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir ↗Metasploit600
Oracle WebLogic wls-wsat Component Deserialization RCE
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir ↗GitHub PoC
An exploit for Apache Struts CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.