Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.183exploits catalogados
37.028CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.320VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.183 exploits
Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa
28RIESGO
abrir ↗Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or
23RIESGO
abrir ↗Exploit-DB
Apple macOS Sierra 10.12.1 - 'IOFireWireFamily' FireWire Port Denial of Service
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireF
23RIESGO
abrir ↗Exploit-DB
WebKitGTK 2.1.2 (Ubuntu 14.04) - Heap based Buffer Overflow
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RIESGO
abrir ↗GitHub PoC★ 2
CVE-2016-7608: Buffer overflow in IOFireWireFamily.
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireF
23RIESGO
abrir ↗Exploit-DB
ZKTime Web Software 2.0 - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hi
23RIESGO
abrir ↗Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW40
28RIESGO
abrir ↗GitHub PoC★ 2
GitのCommand Injectionの脆弱性を利用してスクリプトを落として実行する例
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situ
83RIESGO
abrir ↗Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through N
28RIESGO
abrir ↗Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on Novi
28RIESGO
abrir ↗Exploit-DB
ZKTime Web Software 2.0 - Improper Access Restrictions
ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a P
23RIESGO
abrir ↗GitHub PoC★ 2
An EXP could run on Windows x64 against CVE-2008-4654.
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir ↗Exploit-DB
QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be t
23RIESGO
abrir ↗Exploit-DB
Mozilla Firefox < 45.0 - 'nsHtml5TreeBuilder' Use-After-Free (EMET 5.52 Bypass)
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox
35RIESGO
abrir ↗Exploit-DB
QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge 40.15063.0.0 Chakra - Incorrect JIT Optimization with TypedArray Setter #3
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'JavascriptFunction::EntryCall' Fails to Handle 'CallInfo' Properly
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'TryUndeleteProperty' Incorrect Usage (Denial of Service)
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
35RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra - Heap Buffer Overflow
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'EmitNew' Integer Overflow
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra - Buffer Overflow
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Invoke Accesses Trait Out-of-Bounds
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF fil
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'InterpreterStackFrame::ProcessLinkFailedAsmJsModule' Incorrectly Re-parses
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra - 'chakra!Js::GlobalObject' Integer overflow
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir ↗Exploit-DB
Microsoft Edge Chakra - NULL Pointer Dereference
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'PreVisitCatch' Missing Call
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'InterpreterStackFrame::ProcessLinkFailedAsmJsModule' Incorrect Usage of 'PushPopFrameHelper' (Denial of Service)
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - Out-of-Bounds Access when Fetching Source
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RIESGO
abrir ↗GitHub PoC
ikmski/CVE-2017-1000117
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.