Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
Exploit-DB
ntop-ng 2.0.151021 - Privilege Escalation
ntopng (aka ntop) before 2.2 allows remote authenticated users to change the login context and gain privileges via the u
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
abrt (Centos 7.1 / Fedora 22) - Local Privilege Escalation
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RIESGO
abrir ↗Metasploit600
Cambium ePMP1000 'ping' Shell via Command Injection (up to v2.5)
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SAP Sybase Adaptive Server Enterprise - XML External Entity Information Disclosure
The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to re
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 5.x - Remote Code Execution
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Race Condition DestroySMWP Use-After-Free (MS15-115)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir ↗Exploit-DB
Oracle Outside In PDF 8.5.2 - Parsing Memory Corruption (1)
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RIESGO
abrir ↗Metasploit600
ABRT sosreport Privilege Escalation
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RIESGO
abrir ↗Exploit-DB
Oracle Outside In PDF 8.5.2 - Parsing Memory Corruption (2)
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RIESGO
abrir ↗Exploit-DB
Acrobat Reader DC 15.008.20082.15957 - '.PDF' Parsing Memory Corruption
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Device Contexts and NtGdiSelectBitmap Use-After-Free (MS15-115)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nvidia Stereoscopic 3D Driver Service 7.17.13.5382 - Arbitrary Run Key Creation
nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Cursor Object Memory Leak (MS15-115)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'ndis.sys' IOCTL 0x170034 (ndis!ndisNsiGetIfNameForIfIndex) Pool Buffer Overflow (MS15-117)
Buffer overflow in the Network Driver Interface Standard (NDIS) implementation in Microsoft Windows Vista SP2, Windows S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! 3.4.4 Component Content History - SQL Injection / Remote Code Execution (Metasploit)
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir ↗GitHub PoC★ 5
Estudo e apresentação do bug CVE-2014-4943 para a disciplina MAC0448
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RIESGO
abrir ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password ha
23RIESGO
abrir ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote authenticated users to bypass intended access r
23RIESGO
abrir ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE have a hardcoded password of root for the root account, whic
28RIESGO
abrir ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE
28RIESGO
abrir ↗Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Chkrootkit - Local Privilege Escalation (Metasploit)
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RIESGO
abrir ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authe
23RIESGO
abrir ↗Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid
23RIESGO
abrir ↗Exploit-DB
ZTE ZXHN H108N R1A / ZXV10 W300 Routers - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_
23RIESGO
abrir ↗Exploit-DB
ZTE ADSL ZXV10 W300 Modems - Multiple Vulnerabilities
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
F5 iControl - 'iCall::Script' Root Command Execution (Metasploit)
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.