Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
Exploit-DB✓ VexDay Proof
Nanopool Claymore Dual Miner 7.3 - Remote Code Execution
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RIESGO
abrir ↗GitHub PoC★ 13
Environment for DynoRoot (CVE-2018-1111)
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir ↗VulnCheck XDB
initial-access
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir ↗Exploit-DB
VirtueMart 3.1.14 - Persistent Cross-Site Scripting
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by
23RIESGO
abrir ↗Exploit-DB
RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scripting
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir ↗Exploit-DB
totemomail Encryption Gateway 6.0.0 Build 371 - Cross-Site Request Forgery
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow
23RIESGO
abrir ↗GitHub PoC★ 5
Windows: heap overflow in jscript.dll in Array.sort
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Token Process Trust SID Access Check Bypass Privilege Escalation
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RIESGO
abrir ↗Exploit-DB
Inteno IOPSYS 2.0 < 4.2.0 - 'p910nd' Remote Command Execution
p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via reques
28RIESGO
abrir ↗Exploit-DB
Rockwell Scada System 27.011 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* bef
33RIESGO
abrir ↗Metasploit600
DHCP Client Command Injection (DynoRoot)
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir ↗GitHub PoC★ 24
Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir ↗GitHub PoC
ISC INN 2.x - Command-Line Buffer Overflow
Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privil
23RIESGO
abrir ↗Exploit-DB
2345 Security Guard 3.7 - '2345NsProtect.sys' Denial of Service
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser
23RIESGO
abrir ↗Exploit-DB
WUZHI CMS 4.1.0 - 'tag[pinyin]' Cross-Site Scripting
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitr
23RIESGO
abrir ↗GitHub PoC★ 16
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 2003 SP2 - 'RRAS' SMB Remote Code Execution
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold,
35RIESGO
abrir ↗Exploit-DB
WUZHI CMS 4.1.0 - 'form[qq_10]' Cross-Site Scripting
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set
23RIESGO
abrir ↗GitHub PoC★ 4
The exploitation for CVE-2018-8897
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir ↗GitHub PoC★ 423
Arbitrary code execution with kernel privileges using CVE-2018-8897.
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir ↗GitHub PoC★ 2
gwolfs/CVE-2018-9995-ModifiedByGwolfs
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir ↗Exploit-DB
Open-AudIT Professional - 2.1.1 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗VulnCheck XDB
initial-access
An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), th
23RIESGO
abrir ↗Exploit-DB
Open-AudIT Community 2.2.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗Exploit-DB
2345 Security Guard 3.7 - '2345BdPcSafe.sys' Denial of Service
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv
23RIESGO
abrir ↗GitHub PoC
SLRNPull Spool Directory Command Line Parameter Buffer Overflow Vulnerability
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges
23RIESGO
abrir ↗GitHub PoC
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, all
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.