Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.961exploits catalogados
36.896CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.475Referência 23.400GitHub PoC 15.245VulnCheck XDB 8946Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.961 exploits
Exploit-DB
Oracle WebCenter FatWire Content Server < 7 - Improper Access Control
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Support
23RIESGO
abrir ↗GitHub PoC★ 6
Detecion for the vulnerability CVE-2017-15944
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir ↗Exploit-DB
Honeywell XL Web Controller - Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earli
23RIESGO
abrir ↗Metasploit600
Windscribe WindscribeService Named Pipe Privilege Escalation
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
38RIESGO
abrir ↗Metasploit500
VLC Media Player MKV Use After Free
VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arb
50RIESGO
abrir ↗VulnCheck XDB
initial-access
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir ↗Metasploit300
MimiPenguin
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned f
18RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung Galaxy S7 Edge - Overflow in OMACP WbXml String Extension Processing
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex
23RIESGO
abrir ↗Exploit-DB
Siemens SCALANCE S613 - Remote Denial of Service
Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 4
23RIESGO
abrir ↗Exploit-DB
Siemens SIMATIC S7-1500 CPU - Remote Denial of Service
Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device
23RIESGO
abrir ↗GitHub PoC★ 167
CVE-2018-8174 - VBScript memory corruption exploit.
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'POP/MOV SS' Privilege Escalation
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Magic Value Type Confusion
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux 4.4.0 < 4.4.0-53 - 'AF_PACKET chocobo_root' Local Privilege Escalation (Metasploit)
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RIESGO
abrir ↗Exploit-DB
Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x
43RIESGO
abrir ↗Exploit-DB
ERPnext 11 - Cross-Site Scripting
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
23RIESGO
abrir ↗VulnCheck XDB
client-side
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir ↗Exploit-DB
MakeMyTrip 7.2.4 - Information Disclosure
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypte
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AMD / ARM / Intel - Speculative Execution Variant 4 Speculative Store Bypass
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux 2.6.30 < 2.6.36-rc8 - Reliable Datagram Sockets (RDS) Privilege Escalation (Metasploit)
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir ↗Exploit-DB
Schneider Electric PLCs - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10
23RIESGO
abrir ↗Exploit-DB
ManageEngine Recovery Manager Plus 5.3 - Cross-Site Scripting
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) all
23RIESGO
abrir ↗Exploit-DB
Microsoft Internet Explorer 11 (Windows 7 x86/x64) - vbscript Code Execution
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir ↗GitHub PoC
My version - Easy File Sharing Web Server 7.2 - 'UserID' - Win 7 'DEP' bypass
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir ↗Exploit-DB
D-Link DSL-3782 - Authentication Bypass
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B0
28RIESGO
abrir ↗VulnCheck XDB
local
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗GitHub PoC★ 499
CVE-2018-8120 Windows LPE exploit
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗GitHub PoC★ 12
CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack
28RIESGO
abrir ↗Exploit-DB
HPE iMC 7.3 - Remote Code Execution (Metasploit)
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E05
28RIESGO
abrir ↗GitHub PoC★ 12
CVE-2018-1111 DynoRoot
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.