Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9001Nuclei 4401Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.324 exploits
Metasploit300
BIND TSIG Query Denial of Service
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RIESGO
abrir ↗GitHub PoC
whiteHat001/cve-2010-3333
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 8.1 Update 2 / 10 10586 (x86/x64) - NtLoadKeyEx User Hive Attachment Point Privilege Escalation (MS16-111)
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - RegLoadAppKey Hive Enumeration Privilege Escalation (MS16-111)
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
28RIESGO
abrir ↗GitHub PoC★ 3
这里保存着我学习CVE-2012-1889这个漏洞的利用所用到的文件
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RIESGO
abrir ↗Metasploit600
MagniComp SysInfo mcsiwrapper Privilege Escalation
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Crash When Freeing Memory After AVC decoding
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635
28RIESGO
abrir ↗Exploit-DB
Exponent CMS 2.3.9 - Blind SQL Injection
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kerberos - Security Feature Bypass (MS16-101)
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JCraft/JSch Java Secure Channel 0.1.53 - Recursive sftp-get Directory Traversal
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allow
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office PowerPoint 2010 - Invalid Pointer Reference
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 20
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RIESGO
abrir ↗GitHub PoC★ 9
0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code Execution / Privesc PoC Exploit For testing purposes only. Do no harm.
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir ↗GitHub PoC★ 163
Public repository for improvements to the EXTRABACON exploit
Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Service
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation - 'vprintproxy.exe' TrueType NAME Tables Heap Buffer Overflow (PoC)
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado Thin
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation - 'vprintproxy.exe' JPEG2000 Images Multiple Memory Corruptions
tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, whe
23RIESGO
abrir ↗Metasploit600
BuilderEngine Arbitrary File Upload Vulnerability and execution
BuilderEngine 3.5.0 RCE via Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗GitHub PoC
research CVE-2016-6662
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetBSD - 'mail.local(8)' Local Privilege Escalation (Metasploit)
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RIESGO
abrir ↗GitHub PoC★ 1
Simple ansible playbook to patch mysql servers against CVE-2016-6662
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir ↗GitHub PoC
MySQL server CVE-2016-6662 patch playbook
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir ↗Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cherry Music 0.35.1 - Arbitrary File Disclosure
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file
23RIESGO
abrir ↗Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX G
23RIESGO
abrir ↗Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline
23RIESGO
abrir ↗Exploit-DB
Open-Xchange App Suite 7.8.2 - Cross-Site Scripting
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical atta
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.