Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
22.786 exploits
Exploit-DB
Cobub Razor 0.8.0 - SQL injection
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a
28RIESGO
abrir ↗Exploit-DB
Microsoft Windows - 'nt!NtQueryFullAttributesFile' Kernel Stack Memory Disclosure
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir ↗Exploit-DB
AMD Plays.tv 1.27.5.0 - 'plays_service.exe' Arbitrary File Execution
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RIESGO
abrir ↗Exploit-DB
MikroTik 6.41.4 - FTP daemon Denial of Service (PoC)
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU a
28RIESGO
abrir ↗Exploit-DB
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Exploit-DB
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir ↗Exploit-DB
Microsoft Credential Security Support Provider - Remote Code Execution
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RIESGO
abrir ↗Exploit-DB
Joomla! Convert Forms version 2.0.3 - Formula Injection (CSV Injection)
The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that
23RIESGO
abrir ↗Exploit-DB
DVD X Player Standard 5.5.3.9 - Buffer Overflow
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RIESGO
abrir ↗Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery (Add Admin)
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin File Upload 4.3.2 - Stored Cross-Site Scripting
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Activity Log 2.4.0 - Stored Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RIESGO
abrir ↗Exploit-DB
Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection A
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin File Upload 4.3.3 - Stored Cross-Site Scripting (PoC)
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
23RIESGO
abrir ↗Exploit-DB
iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
23RIESGO
abrir ↗Exploit-DB
iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
23RIESGO
abrir ↗Exploit-DB
Yahei PHP Prober 0.4.7 - Cross-Site Scripting
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
23RIESGO
abrir ↗Exploit-DB
iScripts SonicBB 1.0 - Reflected Cross-Site Scripting (PoC)
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
23RIESGO
abrir ↗Exploit-DB
WebKit - WebAssembly Parsing Does not Correctly Check Section Order
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RIESGO
abrir ↗Exploit-DB
CyberArk Password Vault < 9.7 / < 10 - Memory Disclosure
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RIESGO
abrir ↗Exploit-DB
WolfCMS 0.8.3.1 - Open Redirection
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attack
23RIESGO
abrir ↗Exploit-DB
CyberArk Password Vault Web Access < 9.9.5 / < 9.10 / 10.1 - Remote Code Execution
The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute
28RIESGO
abrir ↗Exploit-DB
Cobub Razor 0.7.2 - Add New Superuser Account
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/inst
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Background Takeover < 4.1.4 - Directory Traversal
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct
50RIESGO
abrir ↗Exploit-DB
WolfCMS 0.8.3.1 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication
23RIESGO
abrir ↗Exploit-DB
Sophos Endpoint Protection 10.7 - Tamper-Protection Bypass
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKE
23RIESGO
abrir ↗Exploit-DB
LineageOS 14.1 Blueborne - Remote Code Execution
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir ↗Exploit-DB
DotNetNuke DNNarticle Module 11 - Directory Traversal
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and conseque
35RIESGO
abrir ↗Exploit-DB
FiberHome VDSL2 Modem HG 150-UB - Authentication Bypass
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
28RIESGO
abrir ↗Exploit-DB
Sophos Endpoint Protection Control Panel 10.7 - Weak Password Encryption
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Vir
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.