Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.432exploits catalogados
34.424CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.493GitHub PoC 13.618VulnCheck XDB 8198Nuclei 4217Metasploit 3463✓ solo verificadosrecientespopularesriesgo
24.443 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Brush Object Use-After-Free (MS15-061)
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - WindowStation Use-After-Free (MS15-061)
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco AnyConnect Secure Mobility Client 3.1.08009 - Local Privilege Escalation
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'bGetRealizedBrush' Use-After-Free (MS15-097)
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Use-After-Free with Cursor Object (MS15-097)
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'NtGdiStretchBlt' Pool Buffer Overflow (MS15-097)
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'FlashWindowEx' Memory Corruption (MS15-097)
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Use-After-Free with Printer Device Contexts (MS15-097)
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RIESGO
abrir ↗Exploit-DB
SAP NetWeaver < 7.01 - XML External Entity Injection
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'DeferWindowPos' Use-After-Free (MS15-073)
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Null Pointer Dereference with Window Station and Clipboard (MS15-061)
The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'HmgAllocateObjectAttr' Use-After-Free (MS15-061)
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Konica Minolta FTP Utility 1.00 - (Authenticated) CWD Command Overflow (SEH) (Metasploit)
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RIESGO
abrir ↗Exploit-DB
Konica Minolta FTP Utility 1.0 - Remote Command Execution
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RIESGO
abrir ↗Exploit-DB
VBox Satellite Express 2.3.17.3 - Arbitrary Write
The ndvbs module in VBox Communications Satellite Express Protocol 2.3.17.3 allows local users to write to arbitrary phy
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Font Driver Buffer Overflow (MS15-078) (Metasploit)
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ManageEngine OpManager - Remote Code Execution (Metasploit)
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ManageEngine OpManager - Remote Code Execution (Metasploit)
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser a
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android - libstagefright Integer Overflow Remote Code Execution
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Font Driver Buffer Overflow (MS15-078) (Metasploit)
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 S
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to exec
28RIESGO
abrir ↗Exploit-DB
FAROL - SQL Injection
SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Excel 2007/2010/2013 - BIFFRecord Use-After-Free
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compati
35RIESGO
abrir ↗Exploit-DB
Openfire 3.10.2 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to inject
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Media Center - MCL (MS15-100) (Metasploit)
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Task Scheduler - 'DeleteExpiredTaskAfter' File Deletion Privilege Escalation
Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1
35RIESGO
abrir ↗Exploit-DB
Openfire 3.10.2 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to
35RIESGO
abrir ↗Exploit-DB
Openfire 3.10.2 - Privilege Escalation
Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.