Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9001Nuclei 4401Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.324 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows - GDI+ ValidateBitmapInfo Invalid Pointer Arithmetic Out-of-Bounds Reads (MS16-097)
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - GDI+ EMR_EXTTEXTOUTA / EMR_POLYTEXTOUTA Heap Buffer Overflow (MS16-097)
The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - GDI+ DecodeCompressedRLEBitmap Invalid Pointer Arithmetic Out-of-Bounds Write (MS16-097)
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Word 2013/2016 - sprmSdyaTop Denial of Service (MS16-099)
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a craf
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WSO2 Carbon 4.4.5 - Local File Inclusion
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WSO2 Identity Server 5.1.0 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MSHTML!CMultiReadStreamLifetimeManager::ReleaseThreadStateInternal Read AV
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet E
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WSO2 Carbon 4.4.5 - Persistent Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WSO2 Carbon 4.4.5 - Denial of Service / Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RIESGO
abrir ↗Exploit-DB
GitLab - 'impersonate' Feature Privilege Escalation
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8
28RIESGO
abrir ↗Exploit-DB
Claroline < 1.7.7 - Arbitrary File Inclusion
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeo
28RIESGO
abrir ↗Metasploit400
AF_PACKET chocobo_root Privilege Escalation
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RIESGO
abrir ↗Metasploit300
ColoradoFTP Server 1.3 Build 8 Directory Traversal Information Disclosure
ColoradoFTP Server <= 1.3 Build 8 Path Traversal Information Disclosure
63RIESGO
abrir ↗Metasploit300
Zabbix toggle_ids SQL Injection
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQ
40RIESGO
abrir ↗Exploit-DB
SquirrelMail < 1.4.7 - Arbitrary Variable Overwrite
Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overw
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP SAPCAR - Multiple Vulnerabilities
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard l
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP SAPCAR - Multiple Vulnerabilities
SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to ca
23RIESGO
abrir ↗Exploit-DB
vBulletin 5.2.2 - Server-Side Request Forgery
The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Le
28RIESGO
abrir ↗Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependen
50RIESGO
abrir ↗Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users v
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Word 2007/2010/2013/2016 - Out-of-Bounds Read Code Execution (MS16-099)
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote at
35RIESGO
abrir ↗Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem
60RIESGO
abrir ↗Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remot
60RIESGO
abrir ↗Exploit-DB
Xfinity Gateway (Technicolor DPC3941T) - Cross-Site Request Forgery
CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r204217
23RIESGO
abrir ↗Metasploit300
Internet Explorer Iframe Sandbox File Name Disclosure Vulnerability
Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL depending on whether the f
30RIESGO
abrir ↗Metasploit600
Trend Micro Smart Protection Server Exec Remote Code Injection
SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330
30RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 (x86/x64) - Group Policy Privilege Escalation (MS16-072)
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Host Guest Client Redirector - DLL Side Loading (Metasploit)
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 t
43RIESGO
abrir ↗Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticat
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.