Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.573 exploits
Referência
CVE-2018-9160
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RIESGO
abrir ↗Referência✓ VexDay Proof
Gnews Publisher .NET - SQL Injection
SQL injection vulnerability in authors.asp in gNews Publisher allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência
CVE-2018-14728
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RIESGO
abrir ↗Referência
CVE-2018-12710
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (whi
45RIESGO
abrir ↗Referência
CVE-2012-4773
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack
23RIESGO
abrir ↗Referência
CVE-2021-22145
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
60RIESGO
abrir ↗Referência
CVE-2014-3791
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code
60RIESGO
abrir ↗Referência
CVE-2012-4773
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module Amevents - SQL Injection
SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers t
23RIESGO
abrir ↗Referência
CVE-2021-44529
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RIESGO
abrir ↗Referência
CVE-2021-44529
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RIESGO
abrir ↗Referência✓ VexDay Proof
PHP weather 2.2.2 - Local File Inclusion / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to injec
23RIESGO
abrir ↗Referência✓ VexDay Proof
FLDS 1.2a - 'report.php' SQL Injection
SQL injection vulnerability in report.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure
Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Referência
CVE-2021-44596
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an
28RIESGO
abrir ↗Referência
Online Magazine Management System 1.0 - SQLi Authentication Bypass
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel auth
23RIESGO
abrir ↗Referência
CVE-2012-4792
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RIESGO
abrir ↗Referência
CVE-2013-5486
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RIESGO
abrir ↗Referência
CVE-2019-1003030
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir ↗Referência
CVE-2023-32243
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir ↗Referência
CVE-2015-0016
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir ↗Referência
CVE-2015-0016
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir ↗Referência✓ VexDay Proof
Forest Blog 1.3.2 - Remote Database Disclosure
Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote
23RIESGO
abrir ↗Referência
Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. A
23RIESGO
abrir ↗Referência
CVE-2017-16921
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.2
28RIESGO
abrir ↗Referência✓ VexDay Proof
V3 Chat Profiles/Dating Script 3.0.2 - Insecure Cookie Handling
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir ↗Referência✓ VexDay Proof
DELTAScripts PHP Classifieds 7.5 - SQL Injection
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPAlumni - SQL Injection
SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure
Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RIESGO
abrir ↗Referência
CVE-2019-1937
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass Vulnerability
85RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.