Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.596exploits catalogados
36.656CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.212GitHub PoC 15.164VulnCheck XDB 8883Nuclei 4369Metasploit 3493✓ solo verificadosrecientespopularesriesgo
79.596 exploits
Metasploit500
VyOS restricted-shell Escape and Privilege Escalation
A privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execu
23RIESGO
abrir ↗Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any f
28RIESGO
abrir ↗Exploit-DB
Royal TS/X - Information Disclosure
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13
23RIESGO
abrir ↗Metasploit600
Intelliants Subrion CMS 4.2.1 - Authenticated File Upload Bypass to RCE
/panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, beca
50RIESGO
abrir ↗Exploit-DB
Intel (Skylake / Kaby Lake) - 'PortSmash' CPU SMT Side-Channel
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks
23RIESGO
abrir ↗GitHub PoC
bolonobolo/CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir ↗GitHub PoC★ 2
matlink/CVE-2018-17961
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RIESGO
abrir ↗Metasploit400
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning
38RIESGO
abrir ↗Metasploit400
Reliable Datagram Sockets (RDS) rds_atomic_free_op NULL pointer dereference Privilege Escalation
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RIESGO
abrir ↗GitHub PoC★ 80
CVE-2018-8440 standalone exploit
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RIESGO
abrir ↗GitHub PoC★ 2
Fully functional script for brute forcing SSH and trying credentials - CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RIESGO
abrir ↗GitHub PoC★ 10
CVE-2018-2628漏洞工具包
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗Exploit-DB
Microstrategy Web 7 - Cross-Site Scripting / Directory Traversal
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (
23RIESGO
abrir ↗Exploit-DB
Microstrategy Web 7 - Cross-Site Scripting / Directory Traversal
Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subp
43RIESGO
abrir ↗Exploit-DB
xorg-x11-server 1.20.3 - Privilege Escalation
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir ↗GitHub PoC
matlink/cve-2017-1000083-atril-nautilus
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir ↗GitHub PoC
matlink/evince-cve-2017-1000083
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir ↗Exploit-DB
Microstrategy Web 7 - Cross-Site Scripting / Directory Traversal
Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (
38RIESGO
abrir ↗Exploit-DB
SaltOS Erp Crm 3.1 r8126 - SQL Injection
SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.
28RIESGO
abrir ↗Exploit-DB
Point of Sales (POS) in VB.Net MySQL Database 1.0 - SQL Injection
Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
23RIESGO
abrir ↗GitHub PoC★ 1
kastellanos/CVE-2018-7602
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
systemd - 'chown_one()' Dereference Symlinks
systemd: chown_one() can dereference symlinks
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
systemd - 'reexec' State Injection
systemd: reexec state injection: fgets() on overlong lines leads to line splitting
41RIESGO
abrir ↗Exploit-DB
SaltOS Erp Crm 3.1 r8126 - SQL Injection (2)
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
23RIESGO
abrir ↗Exploit-DB
SaltOS Erp Crm 3.1 r8126 - Database File Download
SaltOS 3.1 r8126 contains a database download vulnerability.
23RIESGO
abrir ↗Exploit-DB
School Event Management System 1.0 - Arbitrary File Upload
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RIESGO
abrir ↗Exploit-DB
K-iwi Framework 1775 - SQL Injection
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up
23RIESGO
abrir ↗Exploit-DB
School Attendance Monitoring System 1.0 - SQL Injection
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.ph
23RIESGO
abrir ↗Exploit-DB
Bakeshop Inventory System in VB.Net and MS Access Database 1.0 - SQL Injection
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.