Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
Exploit-DB✓ VexDay Proof
Symantec/Norton AntiVirus - ASPack Remote Heap/Pool Memory Corruption
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple 'EMF CREATECOLORSPACEW' Record Handling (MS16-055)
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir ↗Metasploit600
Magento 2.0.6 Unserialize Remote Code Execution
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' Heap Buffer Overflow in ExtEscape() Triggerable via EMR_EXTESCAPE EMF Record (MS16-055)
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Type Confusion in FileReference Constructor
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB
Meteocontrol WEB’log - Admin Password Disclosure (Metasploit)
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pag
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - JXR Processing Out-of-Bounds Read
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Heap Overflow in ATF Processing Image Reading
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple 'EMF COMMENT_MULTIFORMATS' Record Handling (MS16-055)
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - SetNative Use-After-Free
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Read when Placing Object
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco ASA Software 8.x/9.x - IKEv1 / IKEv2 Buffer Overflow
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RIESGO
abrir ↗Exploit-DB
SAP xMII 15.0 - Directory Traversal
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMI
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dell SonicWALL Scrutinizer 11.01 - methodDetail SQL Injection (Metasploit)
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - '.MP4' Stack Corruption
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB
Apple OS X 10.10.5 - 'rootsh' Local Privilege Escalation
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS
23RIESGO
abrir ↗Exploit-DB
CakePHP Framework 3.2.4 - IP Spoofing
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended u
28RIESGO
abrir ↗Exploit-DB
eXtplorer 2.1.9 - '.ZIP' Directory Traversal
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attack
23RIESGO
abrir ↗GitHub PoC
Test modified buggy poc
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RIESGO
abrir ↗GitHub PoC★ 15
Microsoft Office / COM Object DLL Planting
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Media Center - '.MCL' File Processing Remote Code Execution (MS16-059)
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary
83RIESGO
abrir ↗GitHub PoC★ 78
abdsec/CVE-2016-0801
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RIESGO
abrir ↗Exploit-DB
Google Android Broadcom Wi-Fi Driver - Memory Corruption
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader DC 15.010.20060 - Memory Corruption
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acro
28RIESGO
abrir ↗Metasploit300
Internet Explorer 11 VBScript Engine Memory Corruption
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 - 'WebDAV' Local Privilege Escalation (MS16-016) (2)
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ImageMagick 6.9.3-9 / 7.0.1-0 - 'ImageTragick' Delegate Arbitrary Command Execution (Metasploit)
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.