Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.097exploits catalogados
36.319CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.936GitHub PoC 15.007VulnCheck XDB 8843Nuclei 4361Metasploit 3490✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
Abrt (Fedora 21) - Race Condition
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apport/Abrt (Ubuntu / Fedora) - Local Privilege Escalation
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - casi32 Integer Overflow (Metasploit)
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and bef
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX - 'Rootpipe' Local Privilege Escalation (Metasploit)
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.3.5 - File Copy
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Lenovo System Update - Local Privilege Escalation (Metasploit)
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allo
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX < 10.7.5/10.8.2/10.9.5/10.10.2 - 'Rootpipe' Local Privilege Escalation
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Novell ZENworks Configuration Management 11.3.1 - Remote Code Execution
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SolarWinds Firewall Security Manager 6.6.5 - Client Session Handling (Metasploit)
userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privile
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JBoss Seam 2 - Arbitrary File Upload / Execution (Metasploit)
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin Simple Ads Manager - Multiple SQL Injections
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebGate eDVR Manager 2.6.4 - AudioOnlySiteChannel Stack Buffer Overflow
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebGate eDVR Manager 2.6.4 - SiteChannel Property Stack Buffer Overflow
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebGate eDVR Manager 2.6.4 - Connect Method Stack Buffer Overflow
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ceragon FibeAir IP-10 - SSH Private Key Exposure (Metasploit)
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - ByteArray With Workers Use-After-Free (Metasploit)
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Acunetix 9.5 - OLE Automation Array Remote Code Execution
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox - Proxy Prototype Privileged JavaScript Injection (Metasploit)
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Publish-It - '.PUI' Local Buffer Overflow (SEH) (Metasploit)
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TWiki Debugenableplugins - Remote Code Execution (Metasploit)
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet Single Sign On - Stack Overflow
Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attac
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - PCRE Regex (Metasploit)
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IPass Control Pipe - Remote Command Execution (Metasploit)
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ElasticSearch - Search Groovy Sandbox Bypass (Metasploit)
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Plugin SEO by Yoast 1.7.3.3 - Blind SQL Injection
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash Player - ByteArray UncompressViaZlibVariant Use-After-Free (Metasploit)
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Window
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Text Services Memory Corruption (MS15-020)
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ElasticSearch - Remote Code Execution
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.