Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
Exploit-DB
Mantis Bug Tracker 1.3.10/2.3.0 - Cross-Site Request Forgery
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequen
23RIESGO
abrir ↗Exploit-DB
Secure Auditor 3.0 - Directory Traversal
Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Tra
28RIESGO
abrir ↗Exploit-DB
Tecnovision DLX Spot - SSH Backdoor Access
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users
28RIESGO
abrir ↗Exploit-DB
Oracle PeopleSoft - Server-Side Request Forgery
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChann
23RIESGO
abrir ↗Exploit-DB
Tecnovision DLX Spot - Authentication Bypass
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users
23RIESGO
abrir ↗GitHub PoC
WordPress 4.6 - Remote Code Execution (RCE) PoC Exploit
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗GitHub PoC
Install patch for CVE-2017-0145 AKA WannaCry.
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗Exploit-DB
Tecnovision DLX Spot - SSH Backdoor Access
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users
23RIESGO
abrir ↗Exploit-DB
Tecnovision DLX Spot - Arbitrary File Upload
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users
28RIESGO
abrir ↗Exploit-DB
SAP Business One for Android 1.2.3 - XML External Entity Injection
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RIESGO
abrir ↗Exploit-DB
Joomla! 3.7.0 - 'com_fields' SQL Injection
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗GitHub PoC★ 7
Joomla 3.7 SQL injection (CVE-2017-8917)
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗Exploit-DB
KDE 4/5 - 'KAuth' Local Privilege Escalation
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and le
23RIESGO
abrir ↗Exploit-DB
KDE 4/5 - 'KAuth' Local Privilege Escalation
smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount hel
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 8/8.1/2012 R2 (x64) - 'EternalBlue' SMB Remote Code Execution (MS17-010)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗Exploit-DB
INFOR EAM 11.0 Build 201410 - 'filtervalue' SQL Injection
INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.
23RIESGO
abrir ↗Exploit-DB
INFOR EAM 11.0 Build 201410 - Persistent Cross-Site Scripting via Comment Fields
INFOR EAM V11.0 Build 201410 has XSS via comment fields.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Running Object Table Register ROTFLAGS_ALLOWANYCLIENT Privilege Escalation
Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7/2008 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗Exploit-DB
Oracle PeopleSoft Enterprise PeopleTools < 8.55 - Remote Code Execution Via Blind XML External Entity
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integratio
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS < 10.3.2 - Notifications API Denial of Service
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Notifications"
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - COM Aggregate Marshaler/IRemUnknown2 Type Confusion Privilege Escalation
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Read in Getting TextField Width
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a sh
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Margin Handling Heap Corruption
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser
28RIESGO
abrir ↗Metasploit600
Joomla Component Fields SQLi Remote Code Execution
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - AVC Deblocking Out-of-Bounds Read
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced V
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin PHPMailer 4.6 - Host Header Command Injection (Metasploit)
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗GitHub PoC
cve-2016-0728 exploit and summary
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir ↗GitHub PoC★ 88
CVE-2017-7269 to webshell or shellcode loader
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.