Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.400exploits catalogados
37.193CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.340VulnCheck XDB 9001Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.401 exploits
Exploit-DB
Apache Archiva 1.3.9 - Multiple Cross-Site Request Forgery Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (1)
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player 22.0.0.192 - DefineSprite Memory Corruption
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player 22.0.0.192 - TAG Memory Corruption
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - LMZA Property Decoding Heap Corruption
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - ATF Processing Overflow
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ruby on Rails ActionPack Inline ERB - Code Execution (Metasploit)
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir ↗Exploit-DB
IPS Community Suite 4.1.12.3 - PHP Code Injection
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Bo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 SP1 - 'mrxdav.sys' WebDAV Privilege Escalation (MS16-016) (Metasploit)
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - JXR Processing Double-Free
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir ↗Metasploit600
Tiki Wiki Unauthenticated File Upload Vulnerability
Tiki Wiki <= 15.1 ELFinder Unauthenticated File Upload RCE
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - ATF Image Packing Overflow
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir ↗GitHub PoC
KosukeShimofuji/CVE-2016-5734
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir ↗Metasploit500
NetBSD mail.local Privilege Escalation
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Wget < 1.18 - Arbitrary File Upload / Remote Code Execution
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RIESGO
abrir ↗Metasploit300
WebNMS Framework Server Arbitrary Text File Download
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem
60RIESGO
abrir ↗Metasploit300
WebNMS Framework Server Credential Disclosure
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependen
50RIESGO
abrir ↗Metasploit300
WebNMS Framework Server Credential Disclosure
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem
60RIESGO
abrir ↗Metasploit600
WebNMS Framework Server Arbitrary File Upload
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remot
60RIESGO
abrir ↗Exploit-DB
Python smtplib 2.7.11 / 3.4.4 / 3.5.1 - Man In The Middle StartTLS Stripping
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an e
28RIESGO
abrir ↗GitHub PoC
CVE-2016-4971 written in nodejs
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RIESGO
abrir ↗GitHub PoC★ 1
JBoss Autopwn CVE-2010-0738 JBoss authentication bypass
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ktools Photostore 4.7.5 - Blind SQL Injection
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e
23RIESGO
abrir ↗GitHub PoC★ 363
Exploit that extracts Qualcomm's KeyMaster keys using CVE-2015-6639 and CVE-2016-2431
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows 7 SP1 (x86) - Local Privilege Escalation (MS16-014)
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - Unpacking RAR Multiple Remote Memory Corruptions
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - PowerPoint Misaligned Stream-cache Remote Stack Buffer Overflow (PoC)
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - 'dec2lha Library' Remote Stack Buffer Overflow (PoC)
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - TNEF Decoder Integer Overflow
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); S
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM)
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.