Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
GitHub PoC
Just a couple exploits for CVE-2018-11510
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir ↗VulnCheck XDB
local
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir ↗Metasploit600
Axis Network Camera .srv-to-parhand RCE
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RIESGO
abrir ↗Metasploit600
Axis Network Camera .srv-to-parhand RCE
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RIESGO
abrir ↗Metasploit600
Axis Network Camera .srv-to-parhand RCE
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RIESGO
abrir ↗Exploit-DB
Nikto 2.1.6 - CSV Injection
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S
28RIESGO
abrir ↗VulnCheck XDB
client-side
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir ↗VulnCheck XDB
initial-access
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB
Pale Moon Browser < 27.9.3 - Use After Free (PoC)
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
23RIESGO
abrir ↗GitHub PoC★ 7
Demo-ing CVE-2017-1000253 in a container
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb7
76RIESGO
abrir ↗Exploit-DB
OEcms 3.1 - Cross-Site Scripting
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil
38RIESGO
abrir ↗GitHub PoC★ 87
POC for CVE-2018-0824
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RIESGO
abrir ↗VulnCheck XDB
local
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RIESGO
abrir ↗Exploit-DB
Dimofinf CMS 3.0.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb
23RIESGO
abrir ↗Exploit-DB
Joomla! Component Ek Rishta 2.10 - SQL Injection
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to
23RIESGO
abrir ↗GitHub PoC
MySQL 4.x/5.0 (Linux) - User-Defined Function (UDF) Dynamic Library (2) automation script.
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir ↗GitHub PoC★ 18
empty_list - exploit for p0 issue 1564 (CVE-2018-4243) iOS 11.0 - 11.3.1 kernel r/w
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
DHCP Client - Command Injection 'DynoRoot' (Metasploit)
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir ↗Exploit-DB
MACCMS 10 - Cross-Site Request Forgery (Add User)
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
glibc - 'realpath()' Privilege Escalation (Metasploit)
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - Child Process Restriction Mitigation Bypass
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RIESGO
abrir ↗Exploit-DB
RSLinx Classic and FactoryTalk Linx Gateway - Privilege Escalation
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.
23RIESGO
abrir ↗Exploit-DB
Canon PrintMe EFI - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir ↗Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.