Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.466exploits catalogados
36.589CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.152GitHub PoC 15.107VulnCheck XDB 8883Nuclei 4365Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.386 exploits
Exploit-DB✓ VexDay Proof
HP Intelligent Management - Java Deserialization Remote Code Execution (Metasploit)
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and e
60RIESGO
abrir ↗Exploit-DB
DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma
23RIESGO
abrir ↗Exploit-DB
DomainMOD 4.11.01 - Registrar Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
38RIESGO
abrir ↗Exploit-DB
FreshRSS 1.11.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RIESGO
abrir ↗GitHub PoC
CVE-2014-8682
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow r
50RIESGO
abrir ↗Exploit-DB
Xorg X11 Server (AIX) - Local Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RIESGO
abrir ↗Exploit-DB
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RIESGO
abrir ↗Exploit-DB
OpenSSH < 7.7 - User Enumeration (2)
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Exploit-DB
DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
38RIESGO
abrir ↗Exploit-DB
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - 'find_signature' Heap Out-of-Bounds Read
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/v
28RIESGO
abrir ↗Exploit-DB
DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
38RIESGO
abrir ↗GitHub PoC
CVE-2014-4511
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RIESGO
abrir ↗GitHub PoC
This is an exploitation guide for CVE-2016-2233
Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC serve
28RIESGO
abrir ↗Exploit-DB
CyberArk 9.7 - Memory Disclosure
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RIESGO
abrir ↗GitHub PoC
A VENOM (CVE-2015-3456) Exploit / PoC written in C.
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a
28RIESGO
abrir ↗Exploit-DB
Apache Superset < 0.23 - Remote Code Execution
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RIESGO
abrir ↗GitHub PoC★ 1
A collection of code pertaining to CVE-2016-0728 (various authors)
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir ↗GitHub PoC
CVE-2016-1240 exploit and patch
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RIESGO
abrir ↗GitHub PoC★ 104
CVE-2018-8021 Proof-Of-Concept and Exploit
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RIESGO
abrir ↗GitHub PoC★ 39
PrestaShop (1.6.x <= 1.6.1.23 or 1.7.x <= 1.7.4.4) Back Office Remote Code Execution (CVE-2018-19126)
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file u
28RIESGO
abrir ↗Exploit-DB
xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VBScript - 'rtFilter' Out-of-Bounds Read
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which coul
35RIESGO
abrir ↗Exploit-DB
Schneider Electric PLC - Session Calculation Authentication Bypass
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware ver
35RIESGO
abrir ↗GitHub PoC★ 50
All about CVE-2018-14667; From what it is to how to successfully exploit it.
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir ↗Exploit-DB
PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 enco
23RIESGO
abrir ↗VulnCheck XDB
client-side
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC JIT - 'JSPropertyNameEnumerator' Type Confusion
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.