Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
Metasploit600
ImageMagick Delegate Arbitrary Command Execution
The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams
23RIESGO
abrir ↗Metasploit600
ImageMagick Delegate Arbitrary Command Execution
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗GitHub PoC★ 193
Simple test for the May 2016 OpenSSL padding oracle (CVE-2016-2107)
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a
45RIESGO
abrir ↗GitHub PoC★ 125
QSEE Privilege Escalation Exploit using PRDiag* commands (CVE-2015-6639)
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to
23RIESGO
abrir ↗Exploit-DB
QSEE - PRDiag* Commands Privilege Escalation
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts - Dynamic Method Invocation Remote Code Execution (Metasploit)
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RIESGO
abrir ↗Metasploit600
Allwinner 3.4 Legacy Kernel Local Privilege Escalation
The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privil
18RIESGO
abrir ↗Exploit-DB
PHP 7.0.5 - ZipArchive::getFrom* Integer Overflow
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denia
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k.sys' TTF Processing EBLC / EBSC Tables Pool Corruption (MS16-039)
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
EMC ViPR SRM - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remo
23RIESGO
abrir ↗Metasploit600
Apache Struts Dynamic Method Invocation Remote Code Execution
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RIESGO
abrir ↗Metasploit500
Adobe Flash Player DeleteRangeTimelineOperation Type-Confusion
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - CSRSS BaseSrvCheckVDM Session 0 Process Creation Privilege Escalation (MS16-048)
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,
83RIESGO
abrir ↗Exploit-DB
RomPager 4.34 (Multiple Router Vendors) - 'Misfortune Cookie' Authentication Bypass
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W,
23RIESGO
abrir ↗GitHub PoC★ 85
Exploit code for CVE-2016-1757
Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code
28RIESGO
abrir ↗Exploit-DB
Mach Race OSX - Local Privilege Escalation
Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Advantech Webaccess Dashboard Viewer - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess
60RIESGO
abrir ↗Exploit-DB
libgd 2.1.1 - Signedness Heap Overflow
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Local Privilege Escalation (MS16-032)
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir ↗Exploit-DB
Symantec Brightmail 10.6.0-7 - LDAP Credentials Disclosure (Metasploit)
The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discove
38RIESGO
abrir ↗Exploit-DB
Sony Playstation 4 (PS4) < 2.50 - WebKit Code Execution (PoC)
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 < 10 / 2008 < 2012 R2 (x86/x64) - Local Privilege Escalation (MS16-032) (PowerShell)
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - DrawMenuBarTemp Wild-Write (MS16-039)
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RIESGO
abrir ↗Exploit-DB
modified eCommerce Shopsoftware 2.0.0.0 rev 9678 - Blind SQL Injection
Multiple SQL injection vulnerabilities in modified eCommerce Shopsoftware 2.0.0.0 revision 9678, when the easybill-modul
23RIESGO
abrir ↗GitHub PoC★ 1
b0b0505/CVE-2016-0846-PoC
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.
23RIESGO
abrir ↗Exploit-DB
Novell ServiceDesk - (Authenticated) Arbitrary File Upload (Metasploit)
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remot
50RIESGO
abrir ↗Metasploit600
pfSense authenticated graph status RCE
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_
30RIESGO
abrir ↗Metasploit300
HP Data Protector Encrypted Communication Remote Command Execution
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AirOS 6.x - Arbitrary File Upload
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
85RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Exim - 'perl_startup' Local Privilege Escalation (Metasploit)
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.