Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
Exploit-DB✓ VexDay Proof
Microsoft Windows Defender - 'mpengine.dll' Memory Corruption
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a speci
35RIESGO
abrir ↗Exploit-DB
Joomla! Component JS Jobs 1.2.0 - Cross-Site Scripting
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.
23RIESGO
abrir ↗Exploit-DB
WebRTC - Private IP Leakage (Metasploit)
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client informati
43RIESGO
abrir ↗Exploit-DB
GetSimple CMS 3.3.13 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows rem
23RIESGO
abrir ↗VulnCheck XDB
client-side
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir ↗GitHub PoC★ 7
Flash Exploit Poc
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (1)
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (2)
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (1)
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RIESGO
abrir ↗GitHub PoC
Phusion WebServer 1.0 - Directory Traversal
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RIESGO
abrir ↗GitHub PoC
Phusion WebServer 1.0 - 'URL' Remote Buffer Overflow
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RIESGO
abrir ↗GitHub PoC
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute a
28RIESGO
abrir ↗GitHub PoC
Xerver 2.10 - Multiple Request Denial of Service Vulnerabilities
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request
28RIESGO
abrir ↗GitHub PoC
Airsensor M520 - HTTPd Unauthenticated Remote Denial of Service / Buffer Overflow (PoC)
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RIESGO
abrir ↗GitHub PoC
Cooolsoft PowerFTP Server 2.0 3/2.10 - Multiple Denial of Service Vulnerabilities
Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly exec
28RIESGO
abrir ↗GitHub PoC
Nortel Wireless LAN Access Point 2200 Series - Denial of Service
Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (s
28RIESGO
abrir ↗GitHub PoC
March Networks DVR 3204 - Logfile Information Disclosure
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows r
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome V8 - 'ElementsAccessorBase::CollectValuesOrEntriesImpl' Type Confusion
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote
23RIESGO
abrir ↗Exploit-DB
DLink DIR-601 - Admin Password Disclosure
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticat
23RIESGO
abrir ↗GitHub PoC
Cisco VPN Client - Integer Overflow Denial of Service
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RIESGO
abrir ↗GitHub PoC★ 267
A code demonstrating CVE-2018-0886
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RIESGO
abrir ↗Exploit-DB
OpenCMS 10.5.3 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WampServer 3.1.1 - Cross-Site Scripting / Cross-Site Request Forgery
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or H
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WampServer 3.1.2 - Cross-Site Request Forgery
Wampserver before 3.1.3 has CSRF in add_vhost.php.
23RIESGO
abrir ↗Exploit-DB
Frog CMS 0.9.5 - Cross-Site Request Forgery (Add User)
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CS
23RIESGO
abrir ↗Exploit-DB
OpenCMS 10.5.3 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allow
23RIESGO
abrir ↗GitHub PoC★ 49
An implementation of CVE-2016-0974 for the Nintendo Wii.
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
35RIESGO
abrir ↗GitHub PoC
tomcat7.x远程命令执行
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir ↗Exploit-DB
WordPress Plugin Relevanssi 4.0.4 - Reflected Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin WP Security Audit Log 3.1.1 - Sensitive Information Disclosure
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-securit
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.