Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.360GitHub PoC 15.228VulnCheck XDB 8946Nuclei 4390Metasploit 3501✓ solo verificadosrecientespopularesriesgo
79.900 exploits
GitHub PoC★ 4
CVE-2018-4241: XNU kernel heap overflow due to bad bounds checking in MPTCP for iOS 11 - 11.3.1released by Ian Beer
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RIESGO
abrir ↗GitHub PoC★ 3
Exploit for CVE-2018-10562
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir ↗VulnCheck XDB
initial-access
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyBB Recent Threads Plugin 1.0 - Cross-Site Scripting
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
23RIESGO
abrir ↗Exploit-DB
WebKitGTK+ < 2.21.3 - Crash (PoC)
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RIESGO
abrir ↗Exploit-DB
Pagekit < 1.0.13 - Cross-Site Scripting Code Generator
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RIESGO
abrir ↗Exploit-DB
Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email)
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗GitHub PoC★ 107
Weblogic 反序列化漏洞(CVE-2018-2628)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗Exploit-DB
Linux Kernel < 4.16.11 - 'ext4_read_inline_data()' Memory Corruption
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untruste
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir ↗GitHub PoC
cve-2018-2628 反弹shell
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗GitHub PoC★ 5
ne1llee/cve-2018-8120
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗Exploit-DB
CyberArk < 10 - Memory Disclosure
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RIESGO
abrir ↗Exploit-DB
Zip-n-Go 4.9 - Buffer Overflow (SEH)
MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
23RIESGO
abrir ↗Exploit-DB
EMS Master Calendar < 8.0.0.20180520 - Cross-Site Scripting
Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malici
23RIESGO
abrir ↗Exploit-DB
Brother HL Series Printers 1.15 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB
SearchBlox 8.6.7 - XML External Entity Injection
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to re
28RIESGO
abrir ↗Exploit-DB
GreenCMS 2.3.0603 - Cross-Site Request Forgery (Add Admin)
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php
23RIESGO
abrir ↗Metasploit300
WebKitGTK+ WebKitFaviconDatabase DoS
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RIESGO
abrir ↗Exploit-DB
GreenCMS 2.3.0603 - Cross-Site Request Forgery / Remote Code Execution
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary
23RIESGO
abrir ↗GitHub PoC★ 6
MS Word MS WordPad via IE VBS Engine RCE
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir ↗VulnCheck XDB
client-side
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir ↗GitHub PoC
My version - CloudMe-Sync-1.10.9---Buffer-Overflow-SEH-DEP-Bypass on Win7 x64 CVE-2018-6892
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - EntrySimpleObjectSlotGetter Type Confusion
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir ↗GitHub PoC
My version - [Win10 x64] CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass CVE-2018-6892
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.