Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8959Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
79.980 exploits
Exploit-DB
Adobe Coldfusion 11.0.03.292866 - BlazeDS Java Object Deserialization Remote Code Execution
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir ↗GitHub PoC★ 33
WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote Code Execution vulnerability.
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir ↗VulnCheck XDB
denial-of-service
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RIESGO
abrir ↗Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Privilege Escalation
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Android - 'getpidcon' Permission Bypass in KeyStore Service
In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to loc
23RIESGO
abrir ↗VulnCheck XDB
client-side
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RIESGO
abrir ↗GitHub PoC★ 82
CVE-2018-6389 Exploit In WordPress DoS
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC★ 1
Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗GitHub PoC
A ModSecurity ruleset for detecting potential attacks using CVE-2018-6389
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗Metasploit300
Claymore Dual GPU Miner Format String dos attack
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format strin
50RIESGO
abrir ↗GitHub PoC★ 1
To solve CTFS.me problem
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗GitHub PoC
malware del lado del cliente de explotacion de vulnerabilidad de internet explorer 6.0 SP1 en windows xp SP2. No requiere de consentimiento por parte del usuario y no descarga ningun archivo
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apport/ABRT - 'chroot' Local Privilege Escalation (Metasploit)
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RIESGO
abrir ↗Exploit-DB
Netis WF2419 Router - Cross-Site Scripting
Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.
23RIESGO
abrir ↗GitHub PoC★ 90
Test and exploit for CVE-2017-12542
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir ↗Exploit-DB
Joomla! Component Zh GoogleMap 8.4.0.0 - SQL Injection
SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, ge
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wonder CMS 2.3.1 - Unrestricted File Upload
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir ↗Exploit-DB
Joomla! Component Zh YandexMap 6.2.1.0 - 'id' SQL Injection
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗Exploit-DB
Wonder CMS 2.3.1 - 'Host' Header Injection
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NO
23RIESGO
abrir ↗Exploit-DB
WordPress Core - 'load-scripts.php' Denial of Service
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir ↗Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Local Privilege Escalation
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RIESGO
abrir ↗Exploit-DB
HPE iLO 4 < 2.53 - Add New Administrator User
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir ↗Exploit-DB
Online Voting System - Authentication Bypass
A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password fo
23RIESGO
abrir ↗Exploit-DB
Claymore Dual GPU Miner 10.5 - Format String
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format strin
50RIESGO
abrir ↗Exploit-DB
Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.