Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.095 exploits
Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Type Confusion with switch Statements
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra: JIT - 'OP_Memset' Type Confusion
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra: JIT - 'Lowerer::LowerBoundCheck' Incorrect Integer Overflow Check
Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker t
35RIESGO
abrir ↗Metasploit0
Microsoft Office CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗Exploit-DB
CommuniGatePro 6.1.16 - Cross-Site Scripting
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RIESGO
abrir ↗Exploit-DB
PSFTPd Windows FTP Server 10.0.4 Build 729 - Log Injection / Use-After-Free
A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be
23RIESGO
abrir ↗Metasploit500
Dup Scout Enterprise Login Buffer Overflow
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9
40RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
D-Link DIR-605L < 2.08 - Denial of Service
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
28RIESGO
abrir ↗Exploit-DB
PSFTPd Windows FTP Server 10.0.4 Build 729 - Log Injection / Use-After-Free
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) f
23RIESGO
abrir ↗Exploit-DB
Web Viewer 1.0.0.193 (Samsung SRN-1670D) - Unrestricted File Upload
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_u
50RIESGO
abrir ↗Exploit-DB
IKARUS anti.virus 2.16.7 - 'ntguard_x64' Local Privilege Escalation
In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kirby CMS < 2.5.7 - Cross-Site Scripting
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exist
23RIESGO
abrir ↗GitHub PoC★ 160
Chrome < 62 uxss exploit (CVE-2017-5124)
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject
23RIESGO
abrir ↗GitHub PoC
Python exploit for CVE-2017-16806
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RIESGO
abrir ↗Exploit-DB
Ulterius Server < 1.9.5.0 - Directory Traversal
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RIESGO
abrir ↗Metasploit500
Linux BPF Sign Extension Local Privilege Escalation
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir ↗Metasploit600
Polycom Shell HDX Series Traceroute Command Execution
Polycom HDX Series Telnet Command Injection via lan traceroute
36RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyBB 1.8.13 - Remote Code Execution
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration fi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
MyBB 1.8.13 - Cross-Site Scripting
The installer in MyBB before 1.8.13 has XSS.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection 12.1 - Tamper-Protection Bypass
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a
23RIESGO
abrir ↗Metasploit300
Roundcube TimeZone Authenticated File Disclosure
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 7.1.8 - Heap Buffer Overflow
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian hand
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - 'jscript!JsErrorToString' Use-After-Free
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
35RIESGO
abrir ↗GitHub PoC★ 1
Fork of github.com/spring-projects/spring-data-rest (vulnerable to CVE-2017-8046)
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir ↗Metasploit600
Synology DiskStation Manager smart.cgi Remote Command Execution
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RIESGO
abrir ↗Metasploit300
Samsung Internet Browser SOP Bypass
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
60RIESGO
abrir ↗Exploit-DB
Ametys CMS 4.0.2 - Password Reset
Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to
23RIESGO
abrir ↗Exploit-DB
ManageEngine Applications Manager 13 - SQL Injection
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated
23RIESGO
abrir ↗Exploit-DB
ManageEngine Applications Manager 13 - SQL Injection
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name param
23RIESGO
abrir ↗Metasploit600
pfSense authenticated group member RCE
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_
30RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.