Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
Metasploit600
DIR-850L (Un)authenticated OS Command Exec
On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SER
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Messaging Gateway < 10.6.3-267 - Cross-Site Request Forgery
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one
23RIESGO
abrir ↗Exploit-DB
NoMachine 5.3.9 - Local Privilege Escalation
An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privil
23RIESGO
abrir ↗Exploit-DB
Android Bluetooth - 'Blueborne' Information Leak (1)
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 all
28RIESGO
abrir ↗Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unitrends UEB 9.1 - 'Unitrends bpserverd' Remote Command Execution
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remot
35RIESGO
abrir ↗Metasploit600
Unitrends UEB http api remote code execution
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, w
50RIESGO
abrir ↗Exploit-DB
VMware WorkStation 12.5.5 - Virtual Machine Escape
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 ha
28RIESGO
abrir ↗Metasploit600
Unitrends UEB bpserverd authentication bypass RCE
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers
28RIESGO
abrir ↗Metasploit600
Unitrends UEB http api remote code execution
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir ↗Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unitrends UEB 9.1 - Privilege Escalation
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR env
28RIESGO
abrir ↗Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-296
23RIESGO
abrir ↗Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and appli
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unitrends UEB 9.1 - Authentication Bypass / Remote Command Execution
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir ↗VulnCheck XDB
client-side
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir ↗GitHub PoC★ 8
this tool can generate a exp for cve-2017-8486, it is developed by python
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir ↗Exploit-DB
Microsoft Windows - '.LNK' Shortcut File Code Execution
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir ↗Metasploit600
QNAP Transcode Server Command Execution
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.
23RIESGO
abrir ↗GitHub PoC★ 7
Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RIESGO
abrir ↗GitHub PoC★ 4
CVE-2017-2388: Null-pointer dereference in IOFireWireFamily.
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireF
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VirtualBox 5.1.22 - Windows Process DLL Signature Bypass Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VirtualBox 5.1.22 - Windows Process DLL UNC Path Signature Bypass Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RIESGO
abrir ↗Exploit-DB
DNSTracer 1.9 - Local Buffer Overflow
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir ↗Exploit-DB
Horde Groupware 5.2.21 - Unauthorized File Download
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.