Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.095 exploits
Exploit-DB
Microsoft Windows 10 RS2 (x64) - 'win32kfull!bFill' Pool Overflow
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
76RIESGO
abrir ↗VulnCheck XDB
initial-access
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir ↗GitHub PoC★ 399
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization (2)
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RIESGO
abrir ↗GitHub PoC★ 31
Scan/Exploit Blueborne CVE-2017-0785
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir ↗Exploit-DB
EPESI 1.8.2 rev20170830 - Cross-Site Scripting
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
23RIESGO
abrir ↗Exploit-DB
EPESI 1.8.2 rev20170830 - Cross-Site Scripting
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
23RIESGO
abrir ↗Exploit-DB
Webkit (Safari) - Universal Cross-site Scripting
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RIESGO
abrir ↗GitHub PoC★ 63
Webkit uxss exploit (CVE-2017-7089)
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RIESGO
abrir ↗Exploit-DB
Webkit (Chome < 61) - 'MHTML' Universal Cross-site Scripting
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject
23RIESGO
abrir ↗Metasploit600
Tomcat RCE via JSP Upload Bypass
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir ↗Metasploit600
HP Intelligent Management Java Deserialization RCE
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and e
60RIESGO
abrir ↗VulnCheck XDB
local
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir ↗GitHub PoC
Usbhijacking | CVE-2017-8464
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir ↗Exploit-DB
OpenText Document Sciences xPression 4.5SP1 Patch 13 - 'jobRunId' SQL Injection
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b
23RIESGO
abrir ↗Exploit-DB
Linux Kernel < 4.14.rc3 - Local Denial of Service
The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to
23RIESGO
abrir ↗Exploit-DB
OpenText Document Sciences xPression 4.5SP1 Patch 13 - 'documentId' SQL Injection
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - Heap Overflow
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - 2-byte Heap Overflow
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir ↗Exploit-DB
UCOPIA Wireless Appliance < 5.1.8 - Restricted Shell Escape
The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admi
23RIESGO
abrir ↗Exploit-DB
UCOPIA Wireless Appliance < 5.1.8 - Local Privilege Escalation
The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileg
23RIESGO
abrir ↗Exploit-DB
phpCollab 2.5.1 - SQL Injection
SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗GitHub PoC★ 3
this script is used for hack bluetooth devices CVE 2017 0785 which was done by ARMIS This File is password protected for password contact atusha@gmail.comr
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Qmail SMTP - Bash Environment Variable Injection (Metasploit)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - Integer Underflow
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-su
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
phpCollab 2.5.1 - Arbitrary File Upload
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - Stack Overflow
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - Lack of free() Denial of Service
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - Information Leak
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vect
35RIESGO
abrir ↗GitHub PoC
billa3283/CVE-2017-0213
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.