Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.409exploits catalogados
37.196CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.664GitHub PoC 15.347VulnCheck XDB 9003Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.409 exploits
Exploit-DB
NetUSB - Kernel Stack Buffer Overflow
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung - SecEmailComposer QUICK_REPLY_BACKGROUND Permissions
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung SecEmailUI - Script Injection
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JIRA and HipChat for JIRA Plugin - Velocity Template Injection
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RIESGO
abrir ↗Metasploit600
Atlassian HipChat for Jira Plugin Velocity Template Injection
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung - 'm2m1shot' Kernel Driver Buffer Overflow
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung - 'seiren' Kernel Driver Buffer Overflow
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung fimg2d - FIMG2D_BITBLT_BLIT ioctl Concurrency Flaw
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with A
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.9.5/10.10.5 - 'rsh/libmalloc' Local Privilege Escalation (Metasploit)
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RIESGO
abrir ↗GitHub PoC★ 23
Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Comp
93RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Safari - User-Assisted Applescript Exec Attack (Metasploit)
Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement f
50RIESGO
abrir ↗Metasploit600
Joomla Content History SQLi Remote Code Execution
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir ↗Metasploit600
Joomla Content History SQLi Remote Code Execution
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir ↗Metasploit600
Joomla Content History SQLi Remote Code Execution
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir ↗GitHub PoC
Dockerfile for testing CVE-2014-0160 Heartbleed exploitation.
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Realtyna RPL 8.9.2 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote adm
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Realtyna RPL 8.9.2 - Persistent Cross-Site Scripting / Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
The World Browser 3.0 Final - Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Metasploit300
Joomla com_contenthistory Error-Based SQL Injection
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zpanel - Remote Code Execution (Metasploit)
ZPanel through 10.1.0 has Remote Command Execution
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HTML Compiler - Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - 'IExternalizable.writeExternal' Type Confusion
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535
83RIESGO
abrir ↗Exploit-DB
Belkin N150 Router 1.00.08/1.00.09 - Directory Traversal
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware befor
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nibbleblog 4.0.3 - Arbitrary File Upload (Metasploit)
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RIESGO
abrir ↗Metasploit0
Safari User-Assisted Applescript Exec Attack
Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement f
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - Sandboxed Mount Reparse Point Creation Mitigation Bypass (MS15-111)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir ↗GitHub PoC
Quick and dirty .py for checking (CVE-2015-1635) MS15-034 + DoS attack option
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗VulnCheck XDB
denial-of-service
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗Exploit-DB
ZYXEL PMG5318-B20A - OS Command Injection
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attac
28RIESGO
abrir ↗Exploit-DB
Linux/MIPS Kernel 2.6.36 - 'NetUSB' Remote Code Execution
Stack-based buffer overflow in the run_init_sbus function in the KCodes NetUSB module for the Linux kernel, as used in c
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.