Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
GitHub PoC★ 1
A PoC of CVE-2016-2098 (rails4.2.5.1 / view render)
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir ↗Exploit-DB
Valve Steam 3.42.16.13 - Local Privilege Escalation
Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to m
23RIESGO
abrir ↗Metasploit600
Tiki-Wiki CMS Calendar Command Execution
Tiki Wiki CMS Authenticated Command Injection in Calendar Module
36RIESGO
abrir ↗Exploit-DB
Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock)
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir ↗Metasploit400
Linux Kernel 4.6.3 Netfilter Privilege Escalation
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RIESGO
abrir ↗Metasploit400
Linux Kernel 4.6.3 Netfilter Privilege Escalation
The IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local
18RIESGO
abrir ↗Exploit-DB
Liferay CE < 6.2 CE GA6 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1
23RIESGO
abrir ↗Metasploit600
ActiveMQ web shell upload
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir ↗Metasploit600
Apache Struts REST Plugin With Dynamic Method Invocation Remote Code Execution
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RIESGO
abrir ↗Metasploit600
WordPress WP Mobile Detector 3.5 Shell Upload
WP Mobile Detector <= 3.5 - Arbitrary File Upload
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector A.09.00 - Encrypted Communications Arbitrary Command Execution (Metasploit)
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir ↗GitHub PoC★ 4
MySQL DoS in the Procedure Analyse Function – CVE-2015-4870
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated
35RIESGO
abrir ↗Exploit-DB
MySQL 5.5.45 - procedure analyse Function Denial of Service
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated
35RIESGO
abrir ↗VulnCheck XDB
initial-access
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗GitHub PoC
towelroot
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗Exploit-DB
FreeBSD Kernel (FreeBSD 10.2 < 10.3 x64) - 'SETFKEY' (PoC)
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before
23RIESGO
abrir ↗Exploit-DB
FreeBSD Kernel (FreeBSD 10.2 x64) - 'sendmsg' Kernel Heap Overflow (PoC)
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 2.2.1 - 'DecodeAdpcmImaQT' Buffer Overflow
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allo
28RIESGO
abrir ↗Exploit-DB
Micro Focus Rumba+ 9.4 - Multiple Stack Buffer Overflow Vulnerabilities
Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attacke
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector A.09.00 - Arbitrary Command Execution
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir ↗GitHub PoC★ 6
Magento Unauthorized Remote Code Execution (CVE-2016-4010)
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir ↗Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - SQL Injection
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime - '.mov' Parsing Memory Corruption
QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir ↗Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - Information Disclosure
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RIESGO
abrir ↗GitHub PoC★ 86
Local privilege escalation for OS X 10.10.5 via CVE-2016-1828.
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Magento < 2.0.6 - Arbitrary Unserialize / Arbitrary Write File
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RIESGO
abrir ↗Exploit-DB
SAP xMII 15.0 - Directory Traversal
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMI
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Overflow in Processing Raw 565 Textures
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.