Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.457exploits catalogados
36.589CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.152GitHub PoC 15.098VulnCheck XDB 8883Nuclei 4365Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.386 exploits
Exploit-DB
DomainMOD 4.11.01 - Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
True Key (TK) Windows Client - Privilege Escalation vulnerability
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
True Key (TK) Windows Client - Weak Directory Permission Vulnerability
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ZTE ZXHN H168N - Improper Access Restrictions
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper cha
55RIESGO
abrir ↗Exploit-DB
Kubernetes - (Authenticated) Arbitrary Requests
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗Exploit-DB
Kubernetes - (Unauthenticated) Arbitrary Requests
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗GitHub PoC★ 4
个人整理的Centos7.x + Kubernetes-1.12.3 + Dashboard-1.8.3 无 CVE-2018-1002105 漏洞的master节点全自动快速一键安装部署文件,适用于测试环境,生产环境的快速安装部署
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗GitHub PoC
Microsoft Equation 3.0/Convert python2 to python3
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗VulnCheck XDB
client-side
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir ↗GitHub PoC★ 1
CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗Metasploit600
ThinkPHP Multiple PHP Injection RCEs
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir ↗Metasploit600
ThinkPHP Multiple PHP Injection RCEs
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RIESGO
abrir ↗GitHub PoC★ 179
exp of CVE-2018-15982
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir ↗Exploit-DB
Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
43RIESGO
abrir ↗Metasploit600
Cisco Prime Infrastructure Runrshell Privilege Escalation
Cisco Small Business Switches Privileged Access Vulnerability
55RIESGO
abrir ↗GitHub PoC★ 2
Proof of consept for CVE-2018-17431
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir ↗GitHub PoC★ 13
CVE-2018-15982_PoC
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir ↗GitHub PoC★ 223
PoC for CVE-2018-1002105.
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗GitHub PoC★ 9
Unrestricted file upload in Adobe ColdFusion
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir ↗GitHub PoC
Flash sources for CVE-2018-15982 used by NK
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir ↗GitHub PoC
uzzzval/cve-2004-2167
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RIESGO
abrir ↗GitHub PoC★ 191
Test utility for cve-2018-1002105
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa
35RIESGO
abrir ↗GitHub PoC★ 4
dnsmasq rop exploit with NX bypass
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RIESGO
abrir ↗Exploit-DB
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/rem
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Intelligent Management - Java Deserialization Remote Code Execution (Metasploit)
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and e
60RIESGO
abrir ↗Exploit-DB
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.