Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
Adobe Flash - swapDepths Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - XMLSocket Destructor Not Cleared Before Setting User Data in connect
Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199,
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - textfield.gridFitType Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Overflow in ID3 Tag Parsing
Integer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Flash Player - Integer Overflow in Function.apply
Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Flash - Issues in DefineBitsLossless and DefineBitsLossless2 Leads to Using Uninitialized Memory
Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote attackers t
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager - Authentication Bypass / Code Execution (Metasploit)
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows HTA (HTML Application) - Remote Code Execution (MS14-064)
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache ActiveMQ 5.11.1/5.13.2 - Directory Traversal / Command Execution
Directory traversal vulnerability in the fileserver upload/download functionality for blob messages in Apache ActiveMQ 5
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ISC BIND 9 - TKEY (PoC)
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sudo 1.8.14 (RHEL 5/6/7 / Ubuntu) - 'Sudoedit' Unauthorized Privilege Escalation
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Libuser Library - Multiple Vulnerabilities
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Libuser Library - Multiple Vulnerabilities
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SysAid Help Desk 'rdslogs' - Arbitrary File Upload (Metasploit)
The RdsLogsEntry servlet in SysAid Help Desk before 15.2 does not properly check file extensions, which allows remote at
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Swim Team 1.44.10777 - Arbitrary File Download
Absolute path traversal vulnerability in include/user/download.php in the Swim Team plugin 1.44.10777 for WordPress allo
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Accellion FTA - getStatus verify_oauth_token Command Execution (Metasploit)
Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - opaqueBackground Use-After-Free (Metasploit)
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Western Digital Arkeia < 11.0.12 - Remote Code Execution (Metasploit)
The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to b
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - ByteArray Use-After-Free (Metasploit)
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows an
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin WP E-Commerce Shop Styling 2.5 - Arbitrary File Download
Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attack
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AirLink101 SkyIPCam1620W - OS Command Injection
snwrite.cgi in AirLink101 SkyIPCam1620W Wireless N MPEG4 3GPP network camera with firmware FW_AIC1620W_1.1.0-12_20120709
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AirLive (Multiple Products) - OS Command Injection
cgi_test.cgi in AirLive BU-2015 with firmware 1.03.18, BU-3026 with firmware 1.43, and MD-3025 with firmware 1.81 allows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - Nellymoser Audio Decoding Buffer Overflow (Metasploit)
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - Drawing Fill Shader Memory Corruption (Metasploit)
Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Havij - OLE Automation Array Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - ClientCopyImage Win32k (MS15-051) (Metasploit)
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.