Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
81.270exploits catalogados
37.818CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.482Referência 24.178GitHub PoC 15.557VulnCheck XDB 9108Nuclei 4440Metasploit 3505✓ solo verificadosrecientespopularesriesgo
81.270 exploits
Metasploit300
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of s
50RIESGO
abrir ↗Metasploit300
Java JMX Server Insecure Endpoint Code Execution Scanner
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not r
60RIESGO
abrir ↗Metasploit300
Apple Quicktime 7 Invalid Atom Length Buffer Overflow
Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of s
50RIESGO
abrir ↗Metasploit600
Java JMX Server Insecure Configuration Java Code Execution
The JMX RMI service in VMware vCenter Server 5.0 before u3e, 5.1 before u3b, 5.5 before u3, and 6.0 before u1 does not r
60RIESGO
abrir ↗Metasploit200
Novell Client 2 SP3 nicm.sys Local Privilege Escalation
The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2
38RIESGO
abrir ↗Metasploit200
Kimai v0.9.2 'db_restore.php' SQL Injection
Kimai 0.9.2 db_restore.php SQL Injection
63RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k!EPATHOBJ::pprFlattenRec Uninitialized Next Pointer Testcase
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RIESGO
abrir ↗GitHub PoC★ 30
For the analysis of CVE-2013-2028
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k!EPATHOBJ::pprFlattenRec Uninitialized Next Pointer Testcase
The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Win32k!EPATHOBJ::pprFlattenRec Uninitialized Next Pointer Testcase
20RIESGO
abrir ↗VulnCheck XDB
local
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir ↗GitHub PoC★ 91
original cve-2013-2094 exploit and a rewritten version for educational purposes
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Python RRDtool Module - Function Format String
Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attacker
28RIESGO
abrir ↗Exploit-DB
Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cau
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mutiny 5 - Arbitrary File Upload (Metasploit)
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow
50RIESGO
abrir ↗Exploit-DB
Exponent CMS 2.2.0 Beta 3 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execut
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP Cleanfix - Cross-Site Request Forgery
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Mail On Update - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote at
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Serva 32 TFTP 2.1.0 - Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash
23RIESGO
abrir ↗Metasploit200
Windows EPATHOBJ::pprFlattenRec Local Privilege Escalation
The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windo
98RIESGO
abrir ↗GitHub PoC★ 10
feliam/CVE-2013-2730
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attacke
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jojo CMS - 'search' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote att
23RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attack
83RIESGO
abrir ↗Metasploit300
Mutiny 5 Arbitrary File Read and Delete
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow
50RIESGO
abrir ↗Metasploit600
VMware vCenter Chargeback Manager ImageUploadServlet Arbitrary File Upload
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers t
50RIESGO
abrir ↗Metasploit600
Mutiny 5 Arbitrary File Upload
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jojo CMS - 'x-forwarded-for' HTTP header SQL Injection
SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2
23RIESGO
abrir ↗GitHub PoC★ 24
feliam/CVE-2013-2729
Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attack
83RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ERS Viewer 2011 - '.ERS' File Handling Buffer Overflow (Metasploit)
Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 1
43RIESGO
abrir ↗Exploit-DB
Linux Kernel < 3.8.x - open-time Capability 'file_ns_capable()' Local Privilege Escalation
kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_m
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.