Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
GitHub PoC★ 39
CerberusSecurity/CVE-2017-5689
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari 10.0.3 - 'JSC::CachedCall' Use-After-Free
Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remot
23RIESGO
abrir ↗GitHub PoC★ 2
RedDot CMS versions 7.5 Build 7.5.0.48 and below full database enumeration exploit that takes advantage of a remote SQL injection vulnerability in ioRD.asp.
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and
23RIESGO
abrir ↗Metasploit600
Crypttech CryptoLog Remote Code Execution
CryptoLog Unauthenticated RCE via SQL Injection and Command Injection
63RIESGO
abrir ↗Metasploit600
Serviio Media Server checkStreamUrl Command Execution
Serviio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter
63RIESGO
abrir ↗Metasploit200
WordPress PHPMailer Host Header Command Injection
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Exploit-DB
WordPress Core 4.6 - Remote Code Execution
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Exploit-DB
WordPress Core < 4.7.4 - Unauthorized Password Reset
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for re
28RIESGO
abrir ↗GitHub PoC★ 3
Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RIESGO
abrir ↗GitHub PoC
homjxi0e/CVE-2017-3881-Cisco
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir ↗VulnCheck XDB
initial-access
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ghostscript 9.21 - Type Confusion Arbitrary Command Execution (Metasploit)
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL < 5.6.35 / < 5.7.17 - Integer Overflow
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RIESGO
abrir ↗GitHub PoC★ 29
From SQL injection to root shell with CVE-2016-6662 by MaYaSeVeN
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tuleap Project Wiki 8.3 < 9.6.99.86 - Command Injection
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project W
28RIESGO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗GitHub PoC★ 4
Shellshock POC | CVE-2014-6271 | cgi-bin reverse shell
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Admidio 3.2.8 - Cross-Site Request Forgery
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RIESGO
abrir ↗Metasploit600
Ghostscript Type Confusion Arbitrary Command Execution
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir ↗GitHub PoC
A rebuilt version of the exploit for CVE-2016-1542 and CVE-2016-1543 from insinuator.net
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11.576.14393.0 - 'CStyleSheetArray::BuildListOfMatchedRules' Memory Corruption
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
35RIESGO
abrir ↗GitHub PoC★ 83
CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RIESGO
abrir ↗GitHub PoC★ 83
CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi
60RIESGO
abrir ↗GitHub PoC★ 83
CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir ↗Metasploit600
Symantec Messaging Gateway Remote Code Execution
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an i
60RIESGO
abrir ↗Metasploit600
Jenkins CLI Deserialization
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RIESGO
abrir ↗Metasploit600
October CMS Upload Protection Bypass Code Execution
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise
50RIESGO
abrir ↗Exploit-DB
Oracle E-Business Suite 12.2.3 - 'IESFOOTPRINT' SQL Injection
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Sup
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari - Array concat Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Realtek Audio Driver 6.0.1.7898 (Windows 10) - Dolby Audio X2 Service Privilege Escalation
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.