Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.406exploits catalogados
37.195CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.344VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.407 exploits
Exploit-DB
Microsoft Windows 7 SP1 (x86) - Local Privilege Escalation (MS16-014)
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - Missing Bounds Checks in dec2zip ALPkOldFormatDecompressor::UnShrink
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - Heap Overflow Modifying MIME Messages
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - PowerPoint Misaligned Stream-cache Remote Stack Buffer Overflow (PoC)
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - Unpacking RAR Multiple Remote Memory Corruptions
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - 'dec2lha Library' Remote Stack Buffer Overflow (PoC)
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - TNEF Decoder Integer Overflow
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); S
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6
23RIESGO
abrir ↗Metasploit600
Panda Security PSEvents Privilege Escalation
Panda Security PSEvents.exe Insecure DLL Loading Privilege Escalation
36RIESGO
abrir ↗Metasploit600
Riverbed SteelCentral NetProfiler/NetExpress Remote Code Execution
Riverbed SteelCentral NetProfiler / NetExpress 10.8.7 RCE
63RIESGO
abrir ↗VulnCheck XDB
client-side
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RIESGO
abrir ↗GitHub PoC★ 3
对CVE-2016-0189漏洞补丁的分析
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RIESGO
abrir ↗Metasploit600
SugarCRM REST Unserialize PHP Code Execution
SugarCRM PHP Deserialization RCE
63RIESGO
abrir ↗Metasploit600
phpMyAdmin Authenticated Remote Code Execution
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir ↗VulnCheck XDB
client-side
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RIESGO
abrir ↗Exploit-DB
Wolf CMS 0.8.2 - Arbitrary File Upload (Metasploit)
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir ↗Exploit-DB
Wolf CMS 0.8.2 - Arbitrary File Upload (Metasploit)
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir ↗GitHub PoC★ 114
Proof-of-Concept exploit for CVE-2016-0189 (VBScript Memory Corruption in IE11)
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RIESGO
abrir ↗Exploit-DB
Microsoft Internet Explorer 11 (Windows 10) - VBScript Memory Corruption (MS16-051)
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RIESGO
abrir ↗Exploit-DB
Microsoft Internet Explorer 11 - Garbage Collector Attribute Type Confusion (MS16-063)
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple DIB-Related EMF Record Handlers Heap Out-of-Bounds Reads/Memory Disclosure (MS16-074)
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W
28RIESGO
abrir ↗Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - 'ctcprotocol Servlet' XML External Entity
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel - 'ecryptfs' '/proc/$pid/environ' Local Privilege Escalation
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to ga
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'ATMFD.dll' NamedEscape 0x250C Pool Corruption (MS16-074)
atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wind
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Custom Font Disable Policy Bypass
The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted applica
23RIESGO
abrir ↗Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - Directory Traversal
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary fil
83RIESGO
abrir ↗Exploit-DB
Symphony CMS 2.6.7 - Session Fixation
Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers
23RIESGO
abrir ↗GitHub PoC
CVE-2016-0051 样本库
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.