Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.596exploits catalogados
36.656CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.212GitHub PoC 15.164VulnCheck XDB 8883Nuclei 4369Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.526 exploits
Exploit-DB✓ VexDay Proof
XNU - POSIX Shared Memory Mappings have Incorrect Maximum Protection
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 1
23RIESGO
abrir ↗VulnCheck XDB
client-side
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
True Key (TK) Windows Client - Authentication Abuse vulnerability
41RIESGO
abrir ↗VulnCheck XDB
client-side
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir ↗GitHub PoC★ 4
个人整理的Centos7.x + Kubernetes-1.12.3 + Dashboard-1.8.3 无 CVE-2018-1002105 漏洞的master节点全自动快速一键安装部署文件,适用于测试环境,生产环境的快速安装部署
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗Exploit-DB
Kubernetes - (Authenticated) Arbitrary Requests
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗Exploit-DB
Kubernetes - (Unauthenticated) Arbitrary Requests
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗GitHub PoC
Microsoft Equation 3.0/Convert python2 to python3
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir ↗GitHub PoC★ 179
exp of CVE-2018-15982
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir ↗Metasploit600
ThinkPHP Multiple PHP Injection RCEs
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RIESGO
abrir ↗Metasploit600
ThinkPHP Multiple PHP Injection RCEs
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir ↗Exploit-DB
Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
43RIESGO
abrir ↗Metasploit600
Cisco Prime Infrastructure Runrshell Privilege Escalation
Cisco Small Business Switches Privileged Access Vulnerability
55RIESGO
abrir ↗GitHub PoC★ 2
Proof of consept for CVE-2018-17431
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir ↗VulnCheck XDB
initial-access
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir ↗GitHub PoC★ 223
PoC for CVE-2018-1002105.
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗GitHub PoC★ 13
CVE-2018-15982_PoC
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir ↗GitHub PoC★ 9
Unrestricted file upload in Adobe ColdFusion
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir ↗VulnCheck XDB
initial-access
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir ↗GitHub PoC
Flash sources for CVE-2018-15982 used by NK
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir ↗GitHub PoC★ 191
Test utility for cve-2018-1002105
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir ↗GitHub PoC
uzzzval/cve-2004-2167
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wireshark - 'find_signature' Heap Out-of-Bounds Read
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/v
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa
35RIESGO
abrir ↗GitHub PoC★ 5
dnsmasq rop exploit with NX bypass
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RIESGO
abrir ↗Exploit-DB
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/rem
28RIESGO
abrir ↗Exploit-DB
Dolibarr ERP/CRM 8.0.3 - Cross-Site Scripting
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
23RIESGO
abrir ↗Exploit-DB
FreshRSS 1.11.1 - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.