Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.104GitHub PoC 15.075VulnCheck XDB 8883Nuclei 4365Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.386 exploits
VulnCheck XDB
infoleak
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ghostscript 9.26 - Pseudo-Operator Remote Code Execution
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to
35RIESGO
abrir ↗VulnCheck XDB
initial-access
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RIESGO
abrir ↗Exploit-DB
SirsiDynix e-Library 3.5.x - Cross-Site Scripting
Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.
23RIESGO
abrir ↗Exploit-DB
Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RIESGO
abrir ↗GitHub PoC★ 1
This is a exp of CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Exploit-DB
Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RIESGO
abrir ↗GitHub PoC★ 1
Writeup for CVE-2017-16995 Linux BPF Local Privilege Escalation
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir ↗Exploit-DB
Linux Kernel 4.13 - 'compat_get_timex()' Leak Kernel Pointer
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitiv
23RIESGO
abrir ↗Metasploit300
Microsoft Exchange Privilege Escalation Exploit
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of
23RIESGO
abrir ↗Exploit-DB
GattLib 0.2 - Stack Buffer Overflow
GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
23RIESGO
abrir ↗GitHub PoC★ 1
cve-2018-15961
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir ↗VulnCheck XDB
client-side
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir ↗GitHub PoC
CVE-2015-2794 auto finder
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RIESGO
abrir ↗VulnCheck XDB
initial-access
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir ↗VulnCheck XDB
initial-access
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗GitHub PoC★ 6
praveensutar/CVE-2019-6263-Joomla-POC
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'InitClass' Type Confusion
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'InlineArrayPush' Type Confusion
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'JsBuiltInEngineInterfaceExtensionObject::InjectJsBuiltInLibraryCode' Use-After-Free
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir ↗Exploit-DB
SCP Client - Multiple Vulnerabilities (SSHtranger Things)
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-T
38RIESGO
abrir ↗Exploit-DB
SCP Client - Multiple Vulnerabilities (SSHtranger Things)
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RIESGO
abrir ↗Exploit-DB
Pydio / AjaXplorer < 5.0.4 - (Unauthenticated) Arbitrary File Upload
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir ↗GitHub PoC★ 2
cve-2018-8453 exp
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗GitHub PoC★ 119
cve-2018-8453 exp
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.