Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
Exploit-DB✓ VexDay Proof
Google Chrome - open-vcdiff Out-of-Bounds Read in Browser Process Integer Overflow
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
F5 iControl - 'iCall::Script' Root Command Execution (Metasploit)
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir ↗Exploit-DB
IBM i Access 7.1 - Local Buffer Overflow / Code Execution
Buffer overflow in IBM i Access 7.1 on Windows allows local users to gain privileges via unspecified vectors.
23RIESGO
abrir ↗Metasploit600
Jenkins CLI RMI Java Deserialization Vulnerability
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RIESGO
abrir ↗Exploit-DB
IBM i Access 7.1 - Local Buffer Overflow / Code Execution
Buffer overflow in IBM i Access 7.1 on Windows allows local users to cause a denial of service (application crash) via u
23RIESGO
abrir ↗Exploit-DB
D-Link DIR-816L Wireless Router - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DIR-816L Wireless Router with firmware before 2
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Malformed TrueType Program TTF Font Processing Pool-Based Buffer Overflow (MS15-115)
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Malformed OS/2 Table TTF Font Processing Pool-Based Buffer Overflow (MS15-115)
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RIESGO
abrir ↗Exploit-DB
Arris TG1682G Modem - Persistent Cross-Site Scripting
Arris TG1682G devices with Comcast TG1682_2.0s7_PRODse 10.0.59.SIP.PC20.CT software allow Unauthenticated Stored XSS via
23RIESGO
abrir ↗VulnCheck XDB
initial-access
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗GitHub PoC★ 5
My exploit for kernel exploitation
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir ↗GitHub PoC★ 1
PoC code for vBulletin PreAuth vulnerability
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir ↗Metasploit300
OpenNMS Java Object Unserialization Remote Code Execution
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RIESGO
abrir ↗Metasploit600
IBM WebSphere RCE Java Deserialization Vulnerability
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 5.1.x - Remote Code Execution
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir ↗Exploit-DB
OpenSSL - Alternative Chains Certificate Forgery
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly
50RIESGO
abrir ↗Exploit-DB
JSSE - SKIP-TLS
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.
50RIESGO
abrir ↗Metasploit600
vBulletin 5.1.2 Unserialize Code Execution
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung Galaxy S6 - libQjpeg DoIntegralUpsample Crash
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung Galaxy S6 Samsung Gallery - GIF Parsing Crash
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung Galaxy S6 Samsung Gallery - Bitmap Decoding Crash
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung Galaxy S6 - android.media.process Face Recognition Memory Corruption
The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge befo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung - libQjpeg Image Decoding Memory Corruption
The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow
23RIESGO
abrir ↗GitHub PoC★ 1
Joomla! 3.2 to 3.4.4 - SQL Injection (CVE-2015-7297, CVE-2015-7857, and CVE-2015-7858)
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec pcAnywhere 12.5.0 (Windows x86) - Remote Code Execution
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.
35RIESGO
abrir ↗Exploit-DB
AIX 7.1 - 'lquerylv' Local Privilege Escalation
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCM
23RIESGO
abrir ↗Exploit-DB
eBay Magento 1.9.2.1 - PHP FPM XML eXternal Entity Injection
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - NtCreateLowBoxToken Handle Capture Local Denial of Service / Privilege Escalation (MS15-111)
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10
23RIESGO
abrir ↗Exploit-DB
Oxwall 1.7.4 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall before 1.8 allow remote attackers to hijack the aut
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.