Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.459 exploits
Exploit-DB
K7 Ultimate Security K7RKScan.sys 17.0.2019 - Denial Of Service (DoS)
K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of
33RIESGO
abrir ↗Exploit-DB
CodeAstro Online Railway Reservation System 1.0 - Cross Site Scripting (XSS)
CodeAstro Online Railway Reservation System Update Employee Page admin-update-employee.php cross site scripting
33RIESGO
abrir ↗Exploit-DB
Cosy+ firmware 21.2s7 - Command Injection
Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due
41RIESGO
abrir ↗Exploit-DB
Typecho 1.3.0 - Race Condition
Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerabil
33RIESGO
abrir ↗Exploit-DB
Centron 19.04 - Remote Code Execution (RCE)
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
28RIESGO
abrir ↗Exploit-DB
Typecho 1.3.0 - Stored Cross-Site Scripting (XSS)
A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or
41RIESGO
abrir ↗Exploit-DB
PZ Frontend Manager WordPress Plugin 1.0.5 - Cross Site Request Forgery (CSRF)
pz-frontend-manager < 1.0.6 - CSRF change user profile picture
41RIESGO
abrir ↗Exploit-DB
Apache HugeGraph Server 1.2.0 - Remote Code Execution (RCE)
Apache HugeGraph-Server: Command execution in gremlin
100RIESGO
abrir ↗Exploit-DB
Intelight X-1L Traffic controller Maxtime 1.9.6 - Remote Code Execution (RCE)
An issue in Intelight X-1L Traffic controller Maxtime v.1.9.6 allows a remote attacker to execute arbitrary code via the
48RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DocsGPT 0.12.0 - Remote Code Execution
Remote Code Execution in DocsGPT
68RIESGO
abrir ↗Exploit-DB
Artica Proxy 4.50 - Remote Code Execution (RCE)
Artica Proxy Unauthenticated PHP Deserialization Vulnerability
85RIESGO
abrir ↗Exploit-DB
Zohocorp ManageEngine ADManager Plus 7210 - Elevation of Privilege
Privilege Escalation
41RIESGO
abrir ↗Exploit-DB
ResidenceCMS 2.10.1 - Stored Cross-Site Scripting (XSS)
A stored cross-site scripting (XSS) vulnerability exists in ResidenceCMS 2.10.1 that allows a low-privilege user to crea
33RIESGO
abrir ↗Exploit-DB
InfluxDB OSS 2.7.11 - Operator Token Privilege Escalation
InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows aut
48RIESGO
abrir ↗Exploit-DB
Sony XAV-AX5500 1.13 - Firmware Update Validation Remote Code Execution (RCE)
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability
33RIESGO
abrir ↗Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and re
23RIESGO
abrir ↗Exploit-DB
Nagios Xi 5.6.6 - Authenticated Remote Code Execution (RCE)
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir ↗Exploit-DB
GeoVision GV-ASManager 6.1.0.0 - Information Disclosure
Information disclosure vulnerability in Geovision GV-ASManager web application with the version v6.1.0.0 or less, which
46RIESGO
abrir ↗Exploit-DB
jQuery 3.3.1 - Prototype Pollution & XSS Exploit
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir ↗Exploit-DB
Apache Tomcat 11.0.3 - Remote Code Execution
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir ↗Exploit-DB
XWiki Platform 15.10.10 - Remote Code Execution
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗Exploit-DB
YesWiki 4.5.1 - Unauthenticated Path Traversal
Path Traversal allowing arbitrary read of files in Yeswiki
56RIESGO
abrir ↗Exploit-DB
Reservit Hotel 2.1 - Stored Cross-Site Scripting (XSS)
Reservit Hotel < 3.0 - Admin+ Stored XSS
33RIESGO
abrir ↗Exploit-DB
Backup and Staging by WP Time Capsule 1.22.21 - Unauthenticated Arbitrary File Upload
Backup and Staging by WP Time Capsule <= 1.22.21 - Unauthenticated Arbitrary File Upload
85RIESGO
abrir ↗Exploit-DB
Palo Alto Networks Expedition 1.2.90.1 - Admin Account Takeover
Expedition: Missing Authentication Leads to Admin Account Takeover
100RIESGO
abrir ↗Exploit-DB
DataEase 2.4.0 - Database Configuration Information Exposure
DataEase has database configuration information exposure vulnerability
53RIESGO
abrir ↗Exploit-DB
Watcharr 1.43.0 - Remote Code Execution (RCE)
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.