Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS Kernel - UAF Racing getProperty on IOHDIXController and testNetBootMethod on IOHDIXControllerUserClient
Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watch
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in AppleMuxControl.kext
The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - NULL Dereference in CoreCaptureResponder Due to Unchecked Return Value
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in nvCommandQueue::GetHandleIndex in GeForce.kext
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts - REST Plugin With Dynamic Method Invocation Remote Code Execution (Metasploit)
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector A.09.00 - Encrypted Communications Arbitrary Command Execution (Metasploit)
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VideoLAN VLC Media Player 2.2.1 - 'DecodeAdpcmImaQT' Buffer Overflow
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Data Protector A.09.00 - Arbitrary Command Execution
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime - '.mov' Parsing Memory Corruption
QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Magento < 2.0.6 - Arbitrary Unserialize / Arbitrary Write File
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco ASA Software 8.x/9.x - IKEv1 / IKEv2 Buffer Overflow
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec/Norton AntiVirus - ASPack Remote Heap/Pool Memory Corruption
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - JXR Processing Out-of-Bounds Read
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - addProperty Use-After-Free
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Heap Overflow in ATF Processing Image Reading
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - '.MP4' Stack Corruption
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dell SonicWALL Scrutinizer 11.01 - methodDetail SQL Injection (Metasploit)
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple 'EMF COMMENT_MULTIFORMATS' Record Handling (MS16-055)
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple 'EMF CREATECOLORSPACEW' Record Handling (MS16-055)
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' Heap Buffer Overflow in ExtEscape() Triggerable via EMR_EXTESCAPE EMF Record (MS16-055)
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - SetNative Use-After-Free
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Type Confusion in FileReference Constructor
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Read when Placing Object
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Overflow in Processing Raw 565 Textures
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended u
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.