Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.095 exploits
Exploit-DB
WordPress Plugin Hospital Management System - SQL Injection
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin WPAMS - SQL Injection
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin WPCHURCH - SQL Injection
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir ↗Exploit-DB
TicketPlus - Arbitrary File Upload
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
23RIESGO
abrir ↗Exploit-DB
Photo Fusion - Arbitrary File Upload
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS 10.2 - Broadcom Out-of-Bounds Write when Handling 802.11k Neighbor Report Response
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RIESGO
abrir ↗Exploit-DB
Oracle 9i XDB 9.2.0.1 - HTTP PASS Buffer Overflow
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Read in applyToRange
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation co
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Memory Read in MP4 Parsing
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RIESGO
abrir ↗GitHub PoC
Check for Struts Vulnerability CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗VulnCheck XDB
initial-access
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Write in MP4 Edge Processing
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Supervisor 3.0a1 < 3.3.2 - XML-RPC (Authenticated) Remote Code Execution (Metasploit)
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir ↗GitHub PoC★ 11
just a python script for cve-2017-12615
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir ↗GitHub PoC
l0n3rs/CVE-2017-9798
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir ↗GitHub PoC
l0n3rs/CVE-2017-8759
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir ↗Metasploit300
Hikvision IP Camera Unauthenticated Password Change Via Improper Authentication Logic
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗Metasploit300
Unauthenticated information disclosure such as configuration, credentials and camera snapshots of a vulnerable Hikvision IP Camera
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir ↗Metasploit300
CyberLink LabelPrint 2.5 Stack Buffer Overflow
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RIESGO
abrir ↗GitHub PoC★ 19
Blueborne CVE-2017-1000251 PoC for linux machines
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CyberLink LabelPrint < 2.5 - Local Buffer Overflow (SEH Unicode)
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RIESGO
abrir ↗VulnCheck XDB
initial-access
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗GitHub PoC★ 112
POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir ↗GitHub PoC
Metasploit module for Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir ↗GitHub PoC★ 40
CVE-2017-0785 BlueBorne PoC
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir ↗Exploit-DB
Cash Back Comparison Script 1.0 - SQL Injection
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗GitHub PoC
CVE-2017-0785: BlueBorne PoC
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir ↗Exploit-DB
Claydip Airbnb Clone 1.0 - Arbitrary File Upload
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Larav
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.