Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8883Nuclei 4365Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.386 exploits
Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Arbitrary mach Port Name Deallocation in XPC Services due to Invalid mach Message Parsing in _xpc_serializer_unpack
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 XNU - 'vm_map_copy' Optimization which Requires Atomicity isn't Atomic
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Moja
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
macOS XNU - Copy-on-Write Behaviour Bypass via Partial-Page Truncation of File
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Moja
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Kernel Heap Overflow in PF_KEY due to Lack of Bounds Checking when Retrieving Statistics
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3,
23RIESGO
abrir ↗GitHub PoC★ 1
NSE script to scan for Cisco routers vulnerable to CVE-2019-1653
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iOS/macOS 10.13.6 - 'if_ports_used_update_wakeuuid()' 16-byte Uninitialized Kernel Stack Disclosure
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
23RIESGO
abrir ↗GitHub PoC★ 1
Python 3 implementation of an existing CVE-2011-3556 proof of concept (PoC).
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RIESGO
abrir ↗GitHub PoC
Exploit script for Crossfire 1.9.0
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RIESGO
abrir ↗VulnCheck XDB
initial-access
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
33RIESGO
abrir ↗Exploit-DB
Rundeck Community Edition < 3.0.13 - Persistent Cross-Site Scripting
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascrip
23RIESGO
abrir ↗Exploit-DB
AirTies Air5341 Modem 1.0.0.12 - Cross-Site Request Forgery
AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
28RIESGO
abrir ↗Exploit-DB
MyBB IP History Logs Plugin 1.0.2 - Cross-Site Scripting
An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the ad
23RIESGO
abrir ↗Exploit-DB
CloudMe Sync 1.11.2 Buffer Overflow - WoW64 (DEP Bypass)
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir ↗Exploit-DB
LogonBox Limited / Hypersocket Nervepoint Access Manager - (Unauthenticated) Insecure Direct Object Reference
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 thr
23RIESGO
abrir ↗Exploit-DB
Sricam gSOAP 2.8 - Denial of Service
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server
28RIESGO
abrir ↗Exploit-DB
Cisco RV300 / RV320 - Information Disclosure
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir ↗GitHub PoC★ 2
DVR username password recovery.
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-in
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iOS/macOS - 'task_swap_mach_voucher()' Use-After-Free
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir ↗Metasploit600
Schneider Electric Pelco Endura NET55XX Encoder
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RIESGO
abrir ↗Exploit-DB
Lua 5.3.5 - 'debug.upvaluejoin' Use After Free
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attack
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Wisechat 2.6.3 - Reverse Tabnabbing
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPost
23RIESGO
abrir ↗Exploit-DB
Zyxel NBG-418N v2 Modem 1.00(AAXM.6)C0 - Cross-Site Request Forgery
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
23RIESGO
abrir ↗VulnCheck XDB
infoleak
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir ↗Exploit-DB
SirsiDynix e-Library 3.5.x - Cross-Site Scripting
Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ghostscript 9.26 - Pseudo-Operator Remote Code Execution
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to
35RIESGO
abrir ↗VulnCheck XDB
initial-access
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.