Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
22.786 exploits
Exploit-DB
Frog CMS 0.9.5 - Persistent Cross-Site Scripting
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
23RIESGO
abrir ↗Exploit-DB
MyBB Threads to Link Plugin 1.3 - Cross-Site Scripting
An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the opt
23RIESGO
abrir ↗Exploit-DB
October CMS User Plugin 1.4.5 - Persistent Cross-Site Scripting
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam
23RIESGO
abrir ↗Exploit-DB
Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RIESGO
abrir ↗Exploit-DB
Blog Master Pro 1.0 - CSV Injection
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level pri
23RIESGO
abrir ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - (Authenticated) Cross-Site Scripting
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged u
23RIESGO
abrir ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - 'award_id' SQL Injection
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RIESGO
abrir ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - CSV Injection
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RIESGO
abrir ↗Exploit-DB
Shopy Point of Sale 1.0 - CSV Injection
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to
23RIESGO
abrir ↗Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - Local File Inclusion
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.
23RIESGO
abrir ↗Exploit-DB
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir ↗Exploit-DB
ASUS infosvr - Authentication Bypass Command Execution (Metasploit)
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RIESGO
abrir ↗Exploit-DB
Adobe Flash - Overflow when Playing Sound
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitat
28RIESGO
abrir ↗Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any
28RIESGO
abrir ↗Exploit-DB
WSO2 Carbon / WSO2 Dashboard Server 5.3.0 - Persistent Cross-Site Scripting
WSO2 Identity Server before 5.5.0 has XSS via the dashboard, allowing attacks by low-privileged attackers.
35RIESGO
abrir ↗Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and th
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows - Local Privilege Escalation
The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to
23RIESGO
abrir ↗Exploit-DB
Interspire Email Marketer < 6.1.6 - Remote Admin Authentication Bypass
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior
35RIESGO
abrir ↗Exploit-DB
UK Cookie Consent - Persistent Cross-Site Scripting
A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Conse
23RIESGO
abrir ↗Exploit-DB
Easy File Sharing Web Server 7.2 - 'UserID' Remote Buffer Overflow (DEP Bypass)
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir ↗Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
23RIESGO
abrir ↗Exploit-DB
Monstra CMS 3.0.4 - Arbitrary Folder Deletion
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uplo
23RIESGO
abrir ↗Exploit-DB
VLC Media Player/Kodi/PopcornTime 'Red Chimera' < 2.2.5 - Memory Corruption (PoC)
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RIESGO
abrir ↗Exploit-DB
Open-AudIT 2.1 - CSV Macro Injection
Open-AudIT before 2.2 has CSV Injection.
23RIESGO
abrir ↗Exploit-DB
Adobe Flash - Info Leak in Image Inflation
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful expl
28RIESGO
abrir ↗Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that a
23RIESGO
abrir ↗Exploit-DB
Adobe Flash - Out-of-Bounds Write in blur Filtering
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RIESGO
abrir ↗Exploit-DB
Adobe Flash - Overflow in Slab Rendering
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RIESGO
abrir ↗Exploit-DB
Monstra cms 3.0.4 - Persitent Cross-Site Scripting
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload
23RIESGO
abrir ↗Exploit-DB
PRTG Network Monitor < 18.1.39.1648 - Stack Overflow (Denial of Service)
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.