Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
Metasploit300
Juniper SSH Backdoor Scanner
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RIESGO
abrir ↗Metasploit600
TP-Link SC2020n Authenticated Telnet Injection
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models be
60RIESGO
abrir ↗Metasploit600
D-Link DCS-930L Authenticated Remote Command Execution
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in th
98RIESGO
abrir ↗GitHub PoC★ 3
ockeghem/CVE-2015-6835-checker
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_
35RIESGO
abrir ↗Metasploit600
blueman set_dhcp_handler D-Bus Privilege Escalation
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RIESGO
abrir ↗GitHub PoC★ 105
Notes, binaries, and related information from analysis of the CVE-2015-7755 & CVE-2015-7756 issues within Juniper ScreenOS
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - 'TextField' Use-After Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.replaceSel - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 8.1 - 'win32k' Local Privilege Escalation (MS15-010)
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome - Renderer Process to Browser Process Privilege Escalation
Integer overflow in the WebCursor::Deserialize function in content/common/cursors/webcursor.cc in Google Chrome before 4
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash MovieClip.startDrag - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - TextField.Variable Setter Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.tabIndex Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.htmlText Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash MovieClip.attachBitmap - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB
Joomla! 1.5 < 3.4.6 - Object Injection 'x-forwarded-for' Header Remote Code Execution
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.replaceText - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash MovieClip.duplicateMovieClip - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.text Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.setFormat - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.type Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.sharpness Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB
Joomla! 1.5 < 3.4.6 - Object Injection 'x-forwarded-for' Header Remote Code Execution
The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspeci
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.thickness Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Selection.SetSelection - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
win32k Clipboard Bitmap - Use-After-Free
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zen Cart 1.5.4 - Local File Inclusion
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash TextField.gridFitType Setter - Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash MovieClip.lineStyle - Use-After-Frees
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash GradientFill - Use-After-Frees
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.