Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
VulnCheck XDB
initial-access
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir ↗GitHub PoC★ 10
Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Metasploit300
Quest Privilege Manager pmmasterd Buffer Overflow
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full
50RIESGO
abrir ↗Metasploit300
Satel Iberia SenNet Data Logger and Electricity Meters Command Injection Vulnerability
A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataL
23RIESGO
abrir ↗Exploit-DB
Adobe (Multiple Products) - XML Injection File Content Disclosure
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service
100RIESGO
abrir ↗Exploit-DB
Intellinet NFC-30IR Camera - Multiple Vulnerabilities
Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands vi
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information
35RIESGO
abrir ↗Exploit-DB
Intellinet NFC-30IR Camera - Multiple Vulnerabilities
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI scr
28RIESGO
abrir ↗Exploit-DB
D-Link DWR-116 / DWR-116A1 - Arbitrary File Download
Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
35RIESGO
abrir ↗GitHub PoC★ 5
Ruby Exploit for IIS 6.0 Buffer Overflow (CVE-2017-7269)
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗Exploit-DB
Cesanta Mongoose OS - Use-After-Free
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embed
28RIESGO
abrir ↗VulnCheck XDB
initial-access
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗Exploit-DB
Moodle 2.x/3.x - SQL Injection
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
28RIESGO
abrir ↗Metasploit400
MediaWiki SyntaxHighlight extension option injection vulnerability
Parameters injection in SyntaxHighlight results in multiple vulnerabilities
23RIESGO
abrir ↗Metasploit300
TYPO3 News Module SQL Injection
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated
30RIESGO
abrir ↗Metasploit300
HP Jetdirect Path Traversal Arbitrary Code Execution
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RIESGO
abrir ↗Exploit-DB
D-Link DIR-615 - Cross-Site Request Forgery
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacke
23RIESGO
abrir ↗Exploit-DB
SpiceWorks 7.5 TFTP - Remote File Overwrite / Upload
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spicewor
23RIESGO
abrir ↗Exploit-DB
HelpDEZK 1.1.1 - Cross-Site Request Forgery / Code Execution
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
23RIESGO
abrir ↗GitHub PoC★ 92
iis6 exploit 2017 CVE-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗Exploit-DB
HelpDEZK 1.1.1 - Cross-Site Request Forgery / Code Execution
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Faveo Helpdesk Community 1.9.3 - Cross-Site Request Forgery
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS Kernel 10.12.2 (16C67) - Memory Disclosure Due to Lack of Bounds Checking in AppleIntelCapriController::getDisplayPipeCapability
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Webkit - 'JSCallbackData' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issu
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit 10.0.2 - HTMLInputElement Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS Kernel 10.12.2 (16C67) - 'AppleIntelCapriController::GetLinkConfig' Code Execution Due to Lack of Bounds Checking
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit 10.0.2 (12602.3.12.0.1) - 'disconnectSubframes' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.