Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.967GitHub PoC 13.264VulnCheck XDB 8156Nuclei 4201Metasploit 3462✓ solo verificadosrecientespopularesriesgo
22.786 exploits
Exploit-DB
ManageEngine ADManager Plus 6.5.7 - HTML Injection
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
23RIESGO
abrir ↗Exploit-DB
Geutebrueck re_porter 16 - Cross-Site Scripting
A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query
23RIESGO
abrir ↗Exploit-DB
Geutebrueck re_porter 7.8.974.20 - Credential Disclosure
Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information includin
35RIESGO
abrir ↗Exploit-DB
Microsoft Windows 10 - Diagnostics Hub Standard Collector Service Privilege Escalation
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RIESGO
abrir ↗Exploit-DB
OpenSSH 2.3 < 7.7 - Username Enumeration
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Exploit-DB
SEIG Modbus 3.4 - Denial of Service (PoC)
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RIESGO
abrir ↗Exploit-DB
SEIG Modbus 3.4 - Remote Code Execution
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RIESGO
abrir ↗Exploit-DB
Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RIESGO
abrir ↗Exploit-DB
MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Tagregator 0.6 - Cross-Site Scripting
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.
23RIESGO
abrir ↗Exploit-DB
SEIG SCADA System 9 - Remote Code Execution
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote
28RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra JIT - ImplicitCallFlags Check Bypass with Intl
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
45RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra JIT - Parameter Scope Parsing Type Confusion
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
45RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra JIT - 'DictionaryPropertyDescriptor::CopyFrom' Type Confusion
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
45RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra JIT - InitializeNumberFormat and InitializeDateTimeFormat Type Confusion
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
93RIESGO
abrir ↗Exploit-DB
ADM 3.1.2RHG1 - Remote Code Execution
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir ↗Exploit-DB
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir ↗Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick,
23RIESGO
abrir ↗Exploit-DB
OpenSSH 2.3 < 7.7 - Username Enumeration (PoC)
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Exploit-DB
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir ↗Exploit-DB
WebkitGTK+ 2.20.3 - 'ImageBufferCairo::getImageData()' Buffer Overflow (PoC)
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKi
28RIESGO
abrir ↗Exploit-DB
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir ↗Exploit-DB
TP-Link WR840N 0.9.1 3.16 - Denial of Service (PoC)
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
23RIESGO
abrir ↗Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RIESGO
abrir ↗Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati
23RIESGO
abrir ↗Exploit-DB
JioFi 4G M2S 1.0.2 - Denial of Service (PoC)
JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS paylo
23RIESGO
abrir ↗Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability
43RIESGO
abrir ↗Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir ↗Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applicat
28RIESGO
abrir ↗Exploit-DB
Oracle Glassfish OSE 4.1 - Path Traversal (Metasploit)
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.