Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
Exploit-DB
Linux Kernel 4.3.3 - 'overlayfs' Local Privilege Escalation (2)
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir ↗Exploit-DB
Grassroots DICOM (GDCM) 2.6.0 and 2.6.1 - ImageRegionReader::ReadIntoBuffer Buffer Overflow
Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cx
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash (Multiple Scripts) - Use-After-Free When Rendering Displays (1)
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash BlurFilter Processing - Out-of-Bounds Memset
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro - node.js HTTP Server Listening on localhost Can Execute Commands
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url para
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Use-After-Free When Setting Stage
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Konica Minolta FTP Utility 1.00 - CWD Command Overflow (SEH)
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RIESGO
abrir ↗Metasploit300
Fortinet SSH Backdoor Scanner
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0
60RIESGO
abrir ↗GitHub PoC★ 2
cinno/CVE-2015-7755-POC
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RIESGO
abrir ↗Exploit-DB
Fortinet FortiGate 4.x < 5.0.7 - SSH Backdoor Access
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link DCS-931L - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use
50RIESGO
abrir ↗Exploit-DB
OpenMRS Reporting Module 0.9.7 - Remote Code Execution
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a rem
60RIESGO
abrir ↗Exploit-DB
Ganeti - Multiple Vulnerabilities
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11
23RIESGO
abrir ↗Exploit-DB
Ganeti - Multiple Vulnerabilities
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11
28RIESGO
abrir ↗Exploit-DB
Atlassian Confluence 5.2/5.8.14/5.8.15 - Multiple Vulnerabilities
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName p
50RIESGO
abrir ↗Exploit-DB
Atlassian Confluence 5.2/5.8.14/5.8.15 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 4.3.3 (Ubuntu 14.04/15.10) - 'overlayfs' Local Privilege Escalation (1)
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pdfium - CPDF_TextObject::CalcPositionData Heap Out-of-Bounds Read
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pdfium - CPDF_DIBSource::DownSampleScanline32Bit Heap Out-of-Bounds Read
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pdfium - CPDF_Function::Call Stack Buffer Overflow
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RIESGO
abrir ↗GitHub PoC★ 8
All versions of the Joomla! below 3.4.6 are known to be vulnerable. But exploitation is possible with PHP versions below 5.5.29, 5.6.13 and below 5.5.
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir ↗GitHub PoC★ 2
A proof of concept for Joomla's CVE-2015-8562 vulnerability
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (2)
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir ↗Exploit-DB
DeleGate 9.9.13 - Local Privilege Escalation
DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program.
23RIESGO
abrir ↗Exploit-DB
KiTTY Portable 0.65.0.2p (Windows XP/7/10) - Chat Remote Buffer Overflow (SEH)
Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary
28RIESGO
abrir ↗Exploit-DB
PHP 7.0.0 - Format String
Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allow
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - 'infer_pkt_encap' Heap Out-of-Bounds Read
The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - 'AirPDcapDecryptWPABroadcastKey' Heap Out-of-Bounds Read (1)
The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Sound.setTransform - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.