Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
MikroTik RouterOS < 6.43.12 (stable) / < 6.42.12 (long-term) - Firewall and NAT Bypass
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The so
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FaceTime - Texture Processing Memory Corruption
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux - 'kvm_ioctl_create_device()' NULL Pointer Dereference
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DomainMOD 4.11.01 - 'assets/add/dns.php' Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DomainMOD 4.11.01 - 'assets/edit/host.php?whid=5' Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DomainMOD 4.11.01 - 'ssl-accounts.php username' Cross-Site Scripting
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DomainMOD 4.11.01 - 'category.php CatagoryName_ StakeHolder' Cross-Site Scripting
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DomainMOD 4.11.01 - 'ssl-provider-name' Cross-Site Scripting
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Android - binder Use-After-Free of VMA via race Between reclaim and munmap
In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Android - binder Use-After-Free via fdget() Optimization
In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in Po
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NUUO NVRmini - upgrade_handle.php Remote Command Execution (Metasploit)
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Evince - CBT File Command Injection (Metasploit)
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Kernel Heap Overflow in PF_KEY due to Lack of Bounds Checking when Retrieving Statistics
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
macOS XNU - Copy-on-Write Behaviour Bypass via Partial-Page Truncation of File
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Moja
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Arbitrary mach Port Name Deallocation in XPC Services due to Invalid mach Message Parsing in _xpc_serializer_unpack
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Sandbox Escapes due to Type Confusions and Memory Safety Issues in iohideventsystem
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 XNU - 'vm_map_copy' Optimization which Requires Atomicity isn't Atomic
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Moja
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iOS/macOS 10.13.6 - 'if_ports_used_update_wakeuuid()' 16-byte Uninitialized Kernel Stack Disclosure
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iOS/macOS - 'task_swap_mach_voucher()' Use-After-Free
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ghostscript 9.26 - Pseudo-Operator Remote Code Execution
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'InitClass' Type Confusion
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'JsBuiltInEngineInterfaceExtensionObject::InjectJsBuiltInLibraryCode' Use-After-Free
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.