Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
VulnCheck XDB
initial-access
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command inject
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Object.unwatch Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cogent Datahub 7.3.9 Gamma Script - Local Privilege Escalation
Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS - SUID Binary Logic Error Kernel Code Execution
Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Uninitialized Stack Parameter Access in AsBroadcaster.broadcastMessage UaF Fix
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Uninitialized Stack Parameter Access in Object.unwatch UaF Fix
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Shape Rendering Crash
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Code Execution Due to Lack of Bounds Checking in AppleUSBPipe::Abort
IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Zlib Codec Heap Overflow
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows an
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Sprite Creation Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir ↗GitHub PoC
must run this native binary with system privilege
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - AppleKeyStore Use-After-Free
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Unchecked Array Index Used to Read Object Pointer Then Call Virtual Method in Nvidia Geforce Driver
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary c
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Uninitialized Stack Parameter Access in MovieClip.swapDepths UaF Fix
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir ↗GitHub PoC★ 55
Exploitation Training -- CVE-2013-2028: Nginx Stack Based Buffer Overflow
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Use-After-Free and Double Delete Due to Incorrect Locking in Intel GPU Driver
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary co
23RIESGO
abrir ↗Metasploit300
MS16-032 Secondary Logon Handle Privilege Escalation
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 8.1/10 (x86) - Secondary Logon Standard Handles Missing Sanitization Privilege Escalation (MS16-032)
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wildfly - 'WEB-INF' / 'META-INF' Information Disclosure via Filter Restriction Bypass
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RIESGO
abrir ↗GitHub PoC
Cve-2015-1538-1
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir ↗GitHub PoC
dachidahu/CVE-2016-0752
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RIESGO
abrir ↗Exploit-DB
OpenSSH 7.2p1 - (Authenticated) xauth Command Injection
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to
45RIESGO
abrir ↗Metasploit600
BMC Server Automation RSCD Agent NSH Remote Command Execution
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RIESGO
abrir ↗Metasploit600
BMC Server Automation RSCD Agent NSH Remote Command Execution
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a
60RIESGO
abrir ↗Exploit-DB
Cisco UCS Manager 2.1(1b) - Remote Command Injection (Shellshock)
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD 10.2 (x64) - 'amd64_set_ldt' Heap Overflow
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1
23RIESGO
abrir ↗GitHub PoC★ 7
a exploit for cve-2016-0728
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir ↗VulnCheck XDB
local
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir ↗Metasploit600
Kaltura Remote PHP Code Execution
Kaltura < 11.1.0-2 PHP Object Injection RCE
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Read AV in MSHTML!Layout::LayoutBuilderDivider::BuildPageLayout (MS16-023)
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.