Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.557exploits catalogados
37.313CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.478Referência 23.776GitHub PoC 15.367VulnCheck XDB 9019Nuclei 4415Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.557 exploits
Exploit-DB
Google Chrome 43.0 - Certificate MIME Handling Integer Overflow
Multiple unspecified vulnerabilities in Google Chrome before 43.0.2357.65 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Metasploit300
Android Stagefright MP4 tx3g Integer Overflow
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir ↗Exploit-DB
Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injection
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RIESGO
abrir ↗Exploit-DB
Microsoft Windows Server 2003 SP2 - TCP/IP IOCTL Privilege Escalation (MS14-070)
Microsoft Windows Server 2003 SP2 allows local users to gain privileges via a crafted IOCTL call to (1) tcpip.sys or (2)
43RIESGO
abrir ↗Exploit-DB
Microsoft Internet Explorer - CTreeNode::GetCascadedLang Use-After-Free (MS15-079)
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RIESGO
abrir ↗GitHub PoC★ 1
Exploit for CVE-2015-4495 / mfsa2015-78
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RIESGO
abrir ↗VulnCheck XDB
client-side
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
100RIESGO
abrir ↗VulnCheck XDB
denial-of-service
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗GitHub PoC★ 1
PoC for BIND9 TKEY assert DoS (CVE-2015-5477)
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗Metasploit300
Path Traversal in Oracle GlassFish Server Open Source Edition
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir ↗Metasploit300
PCMAN FTP Server Buffer Overflow - PUT Command
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir ↗Exploit-DB
Microsoft Windows XP SP3 (x86) / 2003 SP2 (x86) - 'NDProxy' Local Privilege Escalation (MS14-002)
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RIESGO
abrir ↗Exploit-DB
Dell Netvault Backup 10.0.1.24 - Denial of Service
Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Job Manager 0.7.22 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Job Manager plugin 0.7.22 and earlier for WordPress allows remote attack
23RIESGO
abrir ↗Exploit-DB
ISC BIND 9 - TKEY Remote Denial of Service (PoC)
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗Exploit-DB
Linux Kernel - 'espfix64' Nested NMIs Interrupting Privilege Escalation
arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during n
23RIESGO
abrir ↗GitHub PoC★ 1
Vulnerability as a service: showcasing CVS-2015-5447, a DDoS condition in the bind9 software
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗GitHub PoC★ 14
PoC exploit code for CVE-2015-5477 BIND9 TKEY remote DoS vulnerability
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗Metasploit600
Hak5 WiFi Pineapple Preconfiguration Command Injection
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir ↗Metasploit600
Hak5 WiFi Pineapple Preconfiguration Command Injection
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ISC BIND 9 - TKEY (PoC)
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗GitHub PoC★ 64
PoC exploit for CVE-2015-5477 BIND9 TKEY assertion failure
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RIESGO
abrir ↗Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RIESGO
abrir ↗Metasploit600
Symantec Endpoint Protection Manager Authentication Bypass and Code Execution
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RIESGO
abrir ↗GitHub PoC★ 3
A little Python tool for exploiting CVE-2015-1560 and CVE-2015-1561. Quick'n'dirty. Real dirty.
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis
23RIESGO
abrir ↗VulnCheck XDB
denial-of-service
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗GitHub PoC★ 11
jvazquez-r7/CVE-2015-5119
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir ↗Metasploit300
Heroes of Might and Magic III .h3m Map file Buffer Overflow
Heroes of Might and Magic III .h3m Map File Buffer Overflow
36RIESGO
abrir ↗Metasploit300
BIND TKEY Query Denial of Service
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.