Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.858exploits catalogados
36.825CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.346GitHub PoC 15.209VulnCheck XDB 8944Nuclei 4383Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.697 exploits
VulnCheck XDB
initial-access
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Exploit-DB
Geutebrueck re_porter 16 - Cross-Site Scripting
A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query
23RIESGO
abrir ↗Exploit-DB
Geutebrueck re_porter 7.8.974.20 - Credential Disclosure
Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information includin
35RIESGO
abrir ↗Metasploit600
Apache Struts 2 Namespace Redirect OGNL Injection
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - Diagnostics Hub Standard Collector Service Privilege Escalation
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RIESGO
abrir ↗GitHub PoC★ 3
dangokyo/CVE-2015-5119
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir ↗GitHub PoC★ 111
PoC for Privilege Escalation in Windows 10 Diagnostics Hub Standard Collector Service
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RIESGO
abrir ↗Metasploit600
Ghostscript Failed Restore Command Execution
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RIESGO
abrir ↗GitHub PoC★ 534
Exploit written in Python for CVE-2018-15473 with threading and export formats
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗GitHub PoC
a exp for cve-2018-9948/9958 , current shellcode called win-calc
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH 2.3 < 7.7 - Username Enumeration
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RIESGO
abrir ↗Exploit-DB
MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t
23RIESGO
abrir ↗Exploit-DB
SEIG Modbus 3.4 - Remote Code Execution
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RIESGO
abrir ↗Exploit-DB
WordPress Plugin Tagregator 0.6 - Cross-Site Scripting
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.
23RIESGO
abrir ↗Exploit-DB
SEIG Modbus 3.4 - Denial of Service (PoC)
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RIESGO
abrir ↗Exploit-DB
SEIG SCADA System 9 - Remote Code Execution
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote
28RIESGO
abrir ↗GitHub PoC★ 3
CVE-2018-15473 - Opensshenum is an user enumerator exploiting an OpenSsh bug
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - InitializeNumberFormat and InitializeDateTimeFormat Type Confusion
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
93RIESGO
abrir ↗Exploit-DB
ADM 3.1.2RHG1 - Remote Code Execution
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - ImplicitCallFlags Check Bypass with Intl
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - 'DictionaryPropertyDescriptor::CopyFrom' Type Confusion
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Parameter Scope Parsing Type Confusion
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
45RIESGO
abrir ↗GitHub PoC★ 159
OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Exploit-DB
WebkitGTK+ 2.20.3 - 'ImageBufferCairo::getImageData()' Buffer Overflow (PoC)
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKi
28RIESGO
abrir ↗Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick,
23RIESGO
abrir ↗Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2018-8120 Windows LPE exploit
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.