Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
GitHub PoC★ 41
hexx0r/CVE-2016-0051
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir ↗GitHub PoC★ 70
ImaegMagick Code Execution (CVE-2016-3714)
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗GitHub PoC
NSE plugin for Nmap that scans a DotNetNuke (DNN) web application for an Administration Authentication Bypass vulnerability (CVE-2015-2794, EDB-ID: 39777).
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RIESGO
abrir ↗VulnCheck XDB
initial-access
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - MovieClip.duplicateMovieClip Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DotNetNuke 07.04.00 - Administration Authentication Bypass
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash (Multiple Scripts) - Use-After-Free When Rendering Displays (2)
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RIESGO
abrir ↗GitHub PoC★ 18
jpeanut/ImageTragick-CVE-2016-3714-RShell
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗GitHub PoC
Blind SQL injection brute force.
SQL injection vulnerability in dosearch.inc.php in UBB.threads 7.3.1 and earlier allows remote attackers to execute arbi
23RIESGO
abrir ↗GitHub PoC★ 1
Fix ImageMagick Command Injection (CVE-2016-3714) with Ansible.
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗GitHub PoC
a puppet module in response to CVE-2016-3714
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Ninja Forms 2.9.36 < 2.9.42 - File Upload (Metasploit)
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via
50RIESGO
abrir ↗VulnCheck XDB
client-side
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗Exploit-DB
NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RIESGO
abrir ↗Exploit-DB
NetCommWireless HSPA 3G10WVE Wireless Router - Multiple Vulnerabilities
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CMS Made Simple < 1.12.1 / < 2.1.3 - Web Server Cache Poisoning
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
McAfee LiveSafe 14.0 - Relocations Processing Memory Corruption
Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to c
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSL - Padding Oracle in AES-NI CBC MAC Check
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a
45RIESGO
abrir ↗Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via
28RIESGO
abrir ↗Exploit-DB
Zabbix Agent 3.0.1 - 'mysql.size' Shell Command Injection
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x bef
28RIESGO
abrir ↗Metasploit400
Linux BPF doubleput UAF Privilege Escalation
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly mai
43RIESGO
abrir ↗Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary fi
85RIESGO
abrir ↗Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct
85RIESGO
abrir ↗Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files vi
28RIESGO
abrir ↗Metasploit600
WordPress Ninja Forms Unauthenticated File Upload
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 4.4.x (Ubuntu 16.04) - 'double-fdput()' bpf(BPF_PROG_LOAD) Privilege Escalation
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly mai
43RIESGO
abrir ↗Exploit-DB
ImageMagick 7.0.1-0 / 6.9.3-9 - 'ImageTragick ' Multiple Vulnerabilities
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel (Ubuntu 16.04) - Reference Count Overflow Using BPF Maps
The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a deni
23RIESGO
abrir ↗GitHub PoC
tommiionfire/CVE-2016-3714
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.