Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.596exploits catalogados
36.656CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.212GitHub PoC 15.164VulnCheck XDB 8883Nuclei 4369Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.457 exploits
VulnCheck XDB
initial-access
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir ↗Exploit-DB
OpenSLP 2.0.0 - Multiple Vulnerabilities
Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have
28RIESGO
abrir ↗Exploit-DB
libiec61850 1.3 - Stack Based Buffer Overflow
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_pu
23RIESGO
abrir ↗VulnCheck XDB
local
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled director
100RIESGO
abrir ↗Exploit-DB
CMS Made Simple 2.2.7 - (Authenticated) Remote Code Execution
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
23RIESGO
abrir ↗GitHub PoC★ 14
Exploit for PlaySMS 1.4 authenticated RCE
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FaceTime - 'readSPSandGetDecoderParams' Stack Corruption
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FaceTime - 'VCPDecompressionDecodeFrame' Memory Corruption
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
blueimp's jQuery 9.22.0 - (Arbitrary) File Upload (Metasploit)
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir ↗GitHub PoC★ 21
an RCE (remote command execution) approach of CVE-2018-7750
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RIESGO
abrir ↗VulnCheck XDB
local
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FaceTime - RTP Video Processing Heap Corruption
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1,
23RIESGO
abrir ↗Metasploit500
VyOS restricted-shell Escape and Privilege Escalation
A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu
23RIESGO
abrir ↗Exploit-DB
PHP Proxy 3.0.3 - Local File Inclusion
In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI UR
43RIESGO
abrir ↗Exploit-DB
Royal TS/X - Information Disclosure
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13
23RIESGO
abrir ↗Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir ↗Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f
28RIESGO
abrir ↗Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir ↗Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could
23RIESGO
abrir ↗Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir ↗Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir ↗Metasploit600
Intelliants Subrion CMS 4.2.1 - Authenticated File Upload Bypass to RCE
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir ↗Exploit-DB
Intel (Skylake / Kaby Lake) - 'PortSmash' CPU SMT Side-Channel
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks
23RIESGO
abrir ↗GitHub PoC
bolonobolo/CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RIESGO
abrir ↗GitHub PoC★ 2
matlink/CVE-2018-17961
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
28RIESGO
abrir ↗Metasploit400
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning
43RIESGO
abrir ↗Metasploit400
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RIESGO
abrir ↗GitHub PoC★ 80
CVE-2018-8440 standalone exploit
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RIESGO
abrir ↗GitHub PoC★ 2
Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.