Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
22.786 exploits
Exploit-DB
Zoom Linux Client 2.0.106600.0904 - Stack-Based Buffer Overflow (PoC)
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote
28RIESGO
abrir ↗Exploit-DB
Western Digital MyCloud - 'multi_uploadify' File Upload (Metasploit)
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquer
60RIESGO
abrir ↗Exploit-DB
Zoom Linux Client 2.0.106600.0904 - Command Injection
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when c
28RIESGO
abrir ↗Exploit-DB
Linux kernel < 4.10.15 - Race Condition Privilege Escalation
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denia
28RIESGO
abrir ↗Exploit-DB
Sync Breeze 10.2.12 - Denial of Service
The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The we
23RIESGO
abrir ↗Exploit-DB
Linksys WVBR0 - 'User-Agent' Remote Command Injection
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RIESGO
abrir ↗Exploit-DB
Piwigo 2.9.1 - 'cat_true' / 'cat_false' SQL Injection
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitra
23RIESGO
abrir ↗Exploit-DB
Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Buffer Overflow (Metasploit)
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati
43RIESGO
abrir ↗Exploit-DB
Readymade Video Sharing Script 3.2 - HTML Injection
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RIESGO
abrir ↗Exploit-DB
Palo Alto Networks Firewalls - Root Remote Code Execution
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir ↗Exploit-DB
Paid To Read Script 2.0.5 - 'uid' / 'fnum' / 'fn' SQL Injection
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum para
23RIESGO
abrir ↗Exploit-DB
FS Lynda Clone 1.0 - SQL Injection
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RIESGO
abrir ↗Exploit-DB
Bus Booking Script 1.0 - 'txtname' SQL Injection
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RIESGO
abrir ↗Exploit-DB
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ
23RIESGO
abrir ↗Exploit-DB
vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file delet
28RIESGO
abrir ↗Exploit-DB
Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read
23RIESGO
abrir ↗Exploit-DB
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RIESGO
abrir ↗Exploit-DB
Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
23RIESGO
abrir ↗Exploit-DB
Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RIESGO
abrir ↗Exploit-DB
Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RIESGO
abrir ↗Exploit-DB
Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB
Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RIESGO
abrir ↗Exploit-DB
Apple macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapriController::GetLinkConfig
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RIESGO
abrir ↗Exploit-DB
Apple macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB
Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload
An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper in
28RIESGO
abrir ↗Exploit-DB
Advanced World Database 2.0.5 - SQL Injection
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
23RIESGO
abrir ↗Exploit-DB
Apple macOS/iOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RIESGO
abrir ↗Exploit-DB
MikroTik 6.40.5 ICMP - Denial of Service
MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.
23RIESGO
abrir ↗Exploit-DB
Vanguard 1.4 - Arbitrary File Upload
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product
23RIESGO
abrir ↗Exploit-DB
Resume Clone Script 2.0.5 - SQL Injection
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.