Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.096exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.180 exploits
Exploit-DB
Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir ↗GitHub PoC★ 60
CVE 2017-9805
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Out-of-Bounds Write Privilege Escalation
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (1)
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RIESGO
abrir ↗Metasploit600
Apache Struts 2 REST Plugin XStream RCE
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir ↗Exploit-DB
FiberHome ADSL AN1020-25 - Improper Access Restrictions
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to ea
35RIESGO
abrir ↗Exploit-DB
Wireless Repeater BE126 - Remote Code Execution
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user
23RIESGO
abrir ↗GitHub PoC
siling2017/CVE-2017-1000117
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir ↗Exploit-DB
CodeMeter 6.50 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter befor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RubyGems < 2.6.13 - Arbitrary File Overwrite
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potenti
28RIESGO
abrir ↗Exploit-DB
Mongoose Web Server 6.5 - Cross-Site Request Forgery / Remote Code Execution
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the
23RIESGO
abrir ↗Metasploit600
Mako Server v2.5, 2.6 OS Command Injection RCE
Mako Server v2.5 and v2.6 OS Command Injection via examples/save.lsp
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Notes 8.5.x/9.0.x - Denial of Service
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RIESGO
abrir ↗Exploit-DB
Lotus Notes Diagnostic Tool 8.5/9.0 - Local Privilege Escalation
Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users t
23RIESGO
abrir ↗Exploit-DB
Motorola Bootloader - Kernel Cmdline Injection Secure Boot and Device Locking Bypass
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RIESGO
abrir ↗Metasploit600
Zivif Camera iptest.cgi Blind Remote Command Execution
Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauth
40RIESGO
abrir ↗Exploit-DB
OpenJPEG - 'mqc.c' Heap Buffer Overflow
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Participants Database < 1.7.5.10 - Cross-Site Scripting
The Participants Database plugin before 1.7.5.10 for WordPress has XSS.
23RIESGO
abrir ↗Exploit-DB
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.7 - SQL Injection
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
23RIESGO
abrir ↗Exploit-DB
IBM Notes 8.5.x/9.0.x - Denial of Service (Metasploit)
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Git < 2.7.5 - Command Injection (Metasploit)
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir ↗Exploit-DB
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.6 - SQL Injection
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
23RIESGO
abrir ↗Exploit-DB
Joomla! Component Huge-IT Video Gallery 1.0.9 - SQL Injection
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Notes 8.5.x/9.0.x - Denial of Service (2)
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it woul
43RIESGO
abrir ↗Metasploit300
IBM Notes Denial Of Service
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it woul
43RIESGO
abrir ↗Metasploit300
Open WAN-to-LAN proxy on AT&T routers
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, conf
18RIESGO
abrir ↗Metasploit300
IBM Notes encodeURI DOS
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Metasploit Web UI < 4.14.1-20170828 - Cross-Site Request Forgery
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
23RIESGO
abrir ↗Exploit-DB
Oracle Java JDK/JRE < 1.8.0.131 / Apache Xerces 2.11.0 - 'PDF/Docx' Server Side Denial of Service
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supporte
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.