Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
22.786 exploits
Exploit-DB
Dodocool DC38 N300 - Cross-site Request Forgery
An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A C
23RIESGO
abrir ↗Exploit-DB
BMC BladeLogic 8.3.00.64 - Remote Command Execution
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RIESGO
abrir ↗Exploit-DB
BMC BladeLogic 8.3.00.64 - Remote Command Execution
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a
60RIESGO
abrir ↗Exploit-DB
BMC BladeLogic 8.3.00.64 - Remote Command Execution
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RIESGO
abrir ↗Exploit-DB
Exodus Wallet (ElectronJS Framework) - Remote Code Execution
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RIESGO
abrir ↗Exploit-DB
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Arbitrary File Upload
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir ↗Exploit-DB
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Encryption Keys Disclosure
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir ↗Exploit-DB
GoAhead Web Server 2.5 < 3.6.5 - HTTPd 'LD_PRELOAD' Arbitrary Module Load (Metasploit)
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir ↗Exploit-DB
Kaltura - Remote PHP Code Execution over Cookie (Metasploit)
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, wh
60RIESGO
abrir ↗Exploit-DB
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Arbitrary File Upload
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RIESGO
abrir ↗Exploit-DB
Sync Breeze Enterprise 9.5.16 - 'Import Command' Buffer Overflow (Metasploit)
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RIESGO
abrir ↗Exploit-DB
Professional Local Directory Script 1.0 - SQL Injection
SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter,
28RIESGO
abrir ↗Exploit-DB
Oracle VirtualBox < 5.1.30 / < 5.2-rc1 - Guest to Host Escape
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RIESGO
abrir ↗Exploit-DB
RAVPower 2.000.056 - Root Remote Code Execution
An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a pa
28RIESGO
abrir ↗Exploit-DB
LiveCRM SaaS Cloud 1.0 - SQL Injection
SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.
28RIESGO
abrir ↗Exploit-DB
Flexible Poll 1.2 - SQL Injection
SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.
28RIESGO
abrir ↗Exploit-DB
RAVPower 2.000.056 - Memory Disclosure
RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request.
28RIESGO
abrir ↗Exploit-DB
HP Connected Backup 8.6/8.8.6 - Local Privilege Escalation
A potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6. The vulnerability
23RIESGO
abrir ↗Exploit-DB
Easy Car Script 2014 - SQL Injection
SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php.
23RIESGO
abrir ↗Exploit-DB
Quickad 4.0 - SQL Injection
SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listin
28RIESGO
abrir ↗Exploit-DB
RSVP Invitation Online 1.0 - Cross-Site Request Forgery (Update Admin)
Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modi
23RIESGO
abrir ↗Exploit-DB
Wchat 1.5 - SQL Injection
SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field.
28RIESGO
abrir ↗Exploit-DB
Photography CMS 1.0 - Cross-Site Request Forgery (Add Admin)
Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demons
23RIESGO
abrir ↗Exploit-DB
Tumder 2.1 - SQL Injection
SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the categor
23RIESGO
abrir ↗Exploit-DB
Zechat 1.5 - SQL Injection
SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
23RIESGO
abrir ↗Exploit-DB
AsusWRT Router < 3.0.0.4.380.7743 - LAN Remote Code Execution
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn
60RIESGO
abrir ↗Exploit-DB
AsusWRT Router < 3.0.0.4.380.7743 - LAN Remote Code Execution
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro
60RIESGO
abrir ↗Exploit-DB
OTRS 5.0.x/6.0.x - Remote Command Execution (1)
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.2
28RIESGO
abrir ↗Exploit-DB
PHPFreeChat 1.7 - Denial of Service
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect co
23RIESGO
abrir ↗Exploit-DB
Oracle JDeveloper 11.1.x/12.x - Directory Traversal
Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versi
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.