Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 19.978GitHub PoC 13.282VulnCheck XDB 8176Nuclei 4202Metasploit 3462✓ solo verificadosrecientespopularesriesgo
22.786 exploits
Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of
23RIESGO
abrir ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer d
23RIESGO
abrir ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL p
23RIESGO
abrir ↗Exploit-DB
Wireless Repeater BE126 - Local File Inclusion
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesys
28RIESGO
abrir ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a den
23RIESGO
abrir ↗Exploit-DB
Automated Logic WebCTRL 6.5 - Local Privilege Escalation
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan
23RIESGO
abrir ↗Exploit-DB
IBM OpenAdmin Tool - SOAP welcomeServer PHP Code Execution (Metasploit)
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RIESGO
abrir ↗Exploit-DB
Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL
23RIESGO
abrir ↗Exploit-DB
Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5;
23RIESGO
abrir ↗Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authenticati
23RIESGO
abrir ↗Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB
PDF-XChange Viewer 2.5 Build 314.0 - Code Execution
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code vi
23RIESGO
abrir ↗Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa
28RIESGO
abrir ↗Exploit-DB
PHPMyWind 5.3 - Cross-Site Scripting
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.
23RIESGO
abrir ↗Exploit-DB
WebKitGTK 2.1.2 (Ubuntu 14.04) - Heap based Buffer Overflow
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RIESGO
abrir ↗Exploit-DB
Apple macOS Sierra 10.12.1 - 'IOFireWireFamily' FireWire Port Denial of Service
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireF
23RIESGO
abrir ↗Exploit-DB
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situ
83RIESGO
abrir ↗Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW40
28RIESGO
abrir ↗Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on Novi
28RIESGO
abrir ↗Exploit-DB
QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RIESGO
abrir ↗Exploit-DB
ZKTime Web Software 2.0 - Improper Access Restrictions
ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a P
23RIESGO
abrir ↗Exploit-DB
Mozilla Firefox < 45.0 - 'nsHtml5TreeBuilder' Use-After-Free (EMET 5.52 Bypass)
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.