Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Netgear Routers - Password Disclosure
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Palo Alto Networks Terminal Services Agent 7.0.3-13 - Integer Overflow
Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle OpenJDK Runtime Environment 1.8.0_112-b15 - Java Serialization Denial Of Service
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PageKit 1.0.10 - Password Reset
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the reg
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit)
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/repor
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (2)
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (1)
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Atlassian Confluence < 5.10.6 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android - get_user/put_user (Metasploit)
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Shutter 0.93.1 - Code Execution
/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a cra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPMailer < 5.2.18 - Remote Code Execution
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wampserver 3.0.6 - Insecure File Permissions Privilege Escalation
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH < 7.4 - 'UsePrivilegeSeparation Disabled' Forwarded Unix Domain Sockets Privilege Escalation
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH < 7.4 - agent Protocol Arbitrary Library Loading
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute
53RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - '_kernelrpc_mach_port_insert_right_trap' Kernel Reference Count Leak / Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 / iOS < 10.2 - powerd Arbitrary Port Replacement
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 / iOS < 10.2 - syslogd Arbitrary Port Replacement
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - MSHTML CPasteCommand::ConvertBitmaptoPng Heap Buffer Overflow (MS14-056)
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 Kernel - Writable Privileged IOKit Registry Properties Code Execution
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12 - Double vm_deallocate in Userspace MIG Code Use-After-Free
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory S
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.