Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.776GitHub PoC 15.367VulnCheck XDB 9019Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.557 exploits
VulnCheck XDB
denial-of-service
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir ↗Exploit-DB
OpenLDAP 2.4.42 - ber_get_next Denial of Service
The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a de
28RIESGO
abrir ↗Exploit-DB
Microsoft Windows Media Center - Command Execution (MS15-100)
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir ↗GitHub PoC★ 1
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir ↗Exploit-DB
Synology Video Station 1.5-0757 - Multiple Vulnerabilities
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharact
28RIESGO
abrir ↗Exploit-DB
Synology Video Station 1.5-0757 - Multiple Vulnerabilities
SQL injection vulnerability in Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗VulnCheck XDB
client-side
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Install.Framework - SUID Root Runner Binary Privilege Escalation
Race condition in runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 all
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Install.Framework - Arbitrary mkdir / unlink and chown to Admin Group
runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 does not properly dro
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX - Install.framework suid Helper Privilege Escalation
runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly dro
23RIESGO
abrir ↗GitHub PoC★ 205
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir ↗GitHub PoC★ 12
Archive from the article CVE-2015-5119 Flash ByteArray UaF: A beginner's walkthrough
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir ↗Exploit-DB
Qlikview 11.20 SR11 - Blind XML External Entity Injection
XML external entity (XXE) vulnerability in QlikTech Qlikview before 11.20 SR12 allows remote attackers to conduct server
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.4/5.5/5.6 - SplObjectStorage 'Unserialize()' Use-After-Free
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote
35RIESGO
abrir ↗GitHub PoC★ 3
An exploit for CVE-2015-1538-1 - Google Stagefright ‘stsc’ MP4 Atom Integer Overflow Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Session Deserializer - Use-After-Free
The session deserializer in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 mishandles multiple php_var_
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5.4/5.5/5.6 - SplDoublyLinkedList 'Unserialize()' Use-After-Free
Multiple use-after-free vulnerabilities in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 allow remote
35RIESGO
abrir ↗Exploit-DB
Auto-Exchanger 5.1.0 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Auto-Exchanger 5.1.0 allows remote attackers to hijack the authentica
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android - 'Stagefright' Remote Code Execution
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir ↗GitHub PoC★ 1
drone789/CVE-2012-1823
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir ↗Metasploit600
MS15-100 Microsoft Windows Media Center MCL Vulnerability
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir ↗VulnCheck XDB
initial-access
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir ↗Exploit-DB
Advantech Webaccess 8.0 / 3.4.3 - ActiveX Multiple Vulnerabilities
Multiple stack-based buffer overflows in unspecified DLL files in Advantech WebAccess before 8.0.1 allow remote attacker
23RIESGO
abrir ↗Exploit-DB
JSPMySQL Administrador - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the a
23RIESGO
abrir ↗Exploit-DB
JSPMySQL Administrador - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Endian Firewall - Password Change Command Injection (Metasploit)
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW
50RIESGO
abrir ↗Exploit-DB
WordPress Plugin Contact Form Generator 2.0.1 - Multiple Cross-Site Request Forgery Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for Wo
23RIESGO
abrir ↗GitHub PoC★ 1
Just an attempt to adapt for Note 4, I do not know what I am doing.
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Andr
23RIESGO
abrir ↗Metasploit600
F5 iControl iCall::Script Root Command Execution
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Tenda N3 Wireless N150 Router - Authentication Bypass
Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 and Tenda N3 Wireless N150 devices allow remote attacke
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.