Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.183exploits catalogados
37.028CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.320VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.183 exploits
Exploit-DB
IBM Notes 8.5.x/9.0.x - Denial of Service (Metasploit)
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Metasploit Web UI < 4.14.1-20170828 - Cross-Site Request Forgery
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
23RIESGO
abrir ↗Exploit-DB
Oracle Java JDK/JRE < 1.8.0.131 / Apache Xerces 2.11.0 - 'PDF/Docx' Server Side Denial of Service
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supporte
28RIESGO
abrir ↗Exploit-DB
D-Link DIR-600 - Authentication Bypass
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?RE
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS < 10.3.1 - Kernel
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir ↗Metasploit600
Disk Pulse Enterprise GET Buffer Overflow
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9
40RIESGO
abrir ↗Metasploit300
HP iLO 4 1.00-2.50 Authentication Bypass Administrator Account Creation
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir ↗GitHub PoC
TamiiLambrado/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB
Wireless Repeater BE126 - Local File Inclusion
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesys
28RIESGO
abrir ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of
23RIESGO
abrir ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer d
23RIESGO
abrir ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL p
23RIESGO
abrir ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a den
23RIESGO
abrir ↗Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial
23RIESGO
abrir ↗Exploit-DB
Automated Logic WebCTRL 6.5 - Local Privilege Escalation
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM OpenAdmin Tool - SOAP welcomeServer PHP Code Execution (Metasploit)
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RIESGO
abrir ↗Exploit-DB
Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5;
23RIESGO
abrir ↗Exploit-DB
Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL
23RIESGO
abrir ↗GitHub PoC
test for CVE-2017-1000117
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir ↗GitHub PoC★ 1
There is a classic heap overflow when eval a string which large enough in Chakra! This issue can be reproduced steadly in uptodate Edge in Win10 WIP. An exception will occur immediatly when opening POC.html in Edge.
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir ↗Exploit-DB
PDF-XChange Viewer 2.5 Build 314.0 - Code Execution
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code vi
23RIESGO
abrir ↗Exploit-DB
PHPMyWind 5.3 - Cross-Site Scripting
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.
23RIESGO
abrir ↗Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.