Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.459 exploits
Exploit-DB
Django 5.1.13 - SQL Injection
Potential SQL injection via _connector keyword argument in QuerySet and Q objects
53RIESGO
abrir ↗Exploit-DB
RosarioSIS 6.7.2 - Cross Site Scripting (XSS)
RosarioSIS 6.7.2 is vulnerable to XSS, caused by improper validation of user-supplied input by the Preferences.php scrip
23RIESGO
abrir ↗Exploit-DB
MobileDetect 2.8.31 - Cross-Site Scripting (XSS)
MobileDetect Example session_example.php initLayoutType cross site scripting
28RIESGO
abrir ↗Exploit-DB
PluckCMS 4.7.10 - Unrestricted File Upload
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_resto
41RIESGO
abrir ↗Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery(CSRF)
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.
23RIESGO
abrir ↗Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery (CSRF)
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.
23RIESGO
abrir ↗Exploit-DB
phpMyFaq 2.9.8 - Cross Site Request Forgery (CSRF)
In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.
23RIESGO
abrir ↗Exploit-DB
OpenRepeater 2.1 - OS Command Injection
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_sy
28RIESGO
abrir ↗Exploit-DB
phpMyFAQ 3.1.7 - Reflected Cross-Site Scripting (XSS)
Cross-site Scripting (XSS) - Reflected in thorsten/phpmyfaq
56RIESGO
abrir ↗Exploit-DB
phpIPAM 1.6 - Reflected-Cross-Site Scripting (XSS)
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/admin/powerDNS/record-edit.php.
41RIESGO
abrir ↗Exploit-DB
YOURLS 1.8.2 - Cross-Site Request Forgery (CSRF)
Cross-Site Request Forgery (CSRF) in yourls/yourls
28RIESGO
abrir ↗Exploit-DB
phpIPAM 1.6 - Reflected Cross-Site Scripting (XSS)
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\import-export\import-load-data.php.
33RIESGO
abrir ↗Exploit-DB
Piwigo 13.6.0 - SQL Injection
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
48RIESGO
abrir ↗Exploit-DB
Flowise 3.0.4 - Remote Code Execution (RCE)
Flowise has Remote Code Execution vulnerability
85RIESGO
abrir ↗Exploit-DB
Casdoor 2.95.0 - Cross-Site Request Forgery (CSRF)
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RIESGO
abrir ↗Exploit-DB
ClipBucket 5.5.0 - Arbitrary File Upload
An issue in ClipBucket 5.5.0 and prior versions allows an unauthenticated attacker can exploit the plupload endpoint in
41RIESGO
abrir ↗Exploit-DB
ClipBucket 5.5.2 Build #90 - Server-Side Request Forgery (SSRF)
An issue Clip Bucket v.5.5.2 Build#90 allows a remote attacker to execute arbitrary codes via the file_downloader.php an
33RIESGO
abrir ↗Exploit-DB
Casdoor 2.55.0 - Cross-Site Request Forgery (CSRF)
Casdoor v1.331.0 and below was discovered to contain a Cross-Site Request Forgery (CSRF) in the endpoint /api/set-passwo
23RIESGO
abrir ↗Exploit-DB
Mbed TLS 3.6.4 - Use-After-Free
Mbed TLS before 3.6.4 allows a use-after-free in certain situations of applications that are developed in accordance wit
41RIESGO
abrir ↗Exploit-DB
Concrete CMS 9.4.3 - Stored XSS
Concrete CMS 9 through 9.4.2 is vulnerable to Stored XSS from Home Folder on Members Dashboard page
28RIESGO
abrir ↗Exploit-DB
HTMLDOC 1.9.13 - Stack Buffer Overflow
A stack-based buffer overflow in image_load_bmp() in HTMLDOC <= 1.9.13 results in remote code execution if the victim co
23RIESGO
abrir ↗Exploit-DB
ELEX WooCommerce WordPress Plugin 1.4.3 - SQL Injection
ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction
33RIESGO
abrir ↗Exploit-DB
XWiki Platform 15.10.10 - Metasploit Module for Remote Code Execution (RCE)
Remote code execution as guest via SolrSearchMacros request in xwiki
100RIESGO
abrir ↗Exploit-DB
dotCMS 25.07.02-1 - Authenticated Blind SQL Injection
dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpo
48RIESGO
abrir ↗Exploit-DB
HTTP/2 2.0 - Denial Of Service (DOS)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many
93RIESGO
abrir ↗Exploit-DB
Tourism Management System 2.0 - Arbitrary Shell Upload
A Shell Upload vulnerability in Tourism Management System 2.0 allows an attacker to upload and execute arbitrary PHP she
41RIESGO
abrir ↗Exploit-DB
GeoVision ASManager Windows Application 6.1.2.0 - Credentials Disclosure
GeoVision ASManager Windows desktop application with the version 6.1.2.0 or less (fixed in 6.2.0), is vulnerable to cred
33RIESGO
abrir ↗Exploit-DB
Birth Chart Compatibility WordPress Plugin 2.0 - Full Path Disclosure
Birth Chart Compatibility <= 2.0 - Unauthenticated Full Path Exposure
33RIESGO
abrir ↗Exploit-DB
Ivanti Endpoint Manager Mobile 12.5.0.0 - Authentication Bypass
Authentication Bypass
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.