Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.305 exploits
Exploit-DB✓ VexDay Proof
macOS / iOS NSKeyedUnarchiver - Use-After-Free of ObjC Objects when Unarchiving OITSUIntDictionary Instances
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Memory Corruption when Decoding NSKnownKeysDictionary1
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10
28RIESGO
abrir ↗Metasploit600
Nagios XI Prior to 5.6.6 getprofile.sh Authenticated Remote Command Execution
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass (Metasploit)
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RIESGO
abrir ↗GitHub PoC★ 1
quandqn/cve-2018-14667
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin Simple Membership 3.8.4 - Cross-Site Request Forgery
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
23RIESGO
abrir ↗GitHub PoC★ 4
infiniteLoopers/CVE-2019-2107
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
pdfresurrect 0.15 - Buffer Overflow
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RIESGO
abrir ↗Exploit-DB
Moodle Filepicker 3.5.2 - Server Side Request Forgery
Moodle 3.x has Server Side Request Forgery in the filepicker.
28RIESGO
abrir ↗VulnCheck XDB
initial-access
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RIESGO
abrir ↗Exploit-DB
Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL
28RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RIESGO
abrir ↗Exploit-DB
Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote Code Execution (Metasploit)
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RIESGO
abrir ↗GitHub PoC★ 39
Some debug notes and exploit(not blind)
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RIESGO
abrir ↗GitHub PoC★ 60
EoP POC for CVE-2019-1132
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RIESGO
abrir ↗Exploit-DB
Microsoft Windows 7 build 7601 (x86) - Local Privilege Escalation
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RIESGO
abrir ↗GitHub PoC★ 3
Exim Honey Pot for CVE-2019-10149 exploit attempts.
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗GitHub PoC★ 1
收集网上CVE-2018-0708的poc和exp(目前没有找到exp)
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir ↗VulnCheck XDB
initial-access
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RIESGO
abrir ↗Exploit-DB
Ovidentia 8.4.3 - Cross-Site Scripting
index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=crea
23RIESGO
abrir ↗GitHub PoC★ 10
CVE-2019–11581 PoC
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RIESGO
abrir ↗GitHub PoC★ 14
POC for CVE-2019-14339 Canon PRINT 2.5.5
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - Universal Cross-Site Scripting due to Synchronous Page Loads
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management
23RIESGO
abrir ↗GitHub PoC★ 1
收集网上CVE-2018-0708的poc和exp(目前没有找到exp)
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iMessage - DigitalTouch tap Message Processing Out-of-Bounds Read
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacke
23RIESGO
abrir ↗Exploit-DB
Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir ↗Exploit-DB
Android 7 < 9 - Remote Code Execution
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RIESGO
abrir ↗Exploit-DB
Cisco Wireless Controller 3.6.10E - Cross-Site Request Forgery
Cisco IOS XE NGWC Legacy Wireless Device Manager GUI Cross-Site Request Forgery Vulnerability
46RIESGO
abrir ↗GitHub PoC★ 1
My old sysret / ptrace PoC
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.