Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
Exploit-DB
Tiandy IP Cameras 5.56.17.120 - Sensitive Information Disclosure
Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VirtualBox 5.1.22 - Windows Process DLL UNC Path Signature Bypass Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VirtualBox 5.1.22 - Windows Process DLL Signature Bypass Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RIESGO
abrir ↗Exploit-DB
Dashlane - DLL Hijacking
Dashlane might allow local users to gain privileges by placing a Trojan horse WINHTTP.dll in the %APPDATA%\Dashlane dire
23RIESGO
abrir ↗GitHub PoC★ 67
Support x86 and x64
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nitro Pro PDF Reader 11.0.3.173 - Javascript API Code Execution (Metasploit)
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory tra
50RIESGO
abrir ↗Exploit-DB
libmad 0.15.1b - 'mp3' Memory Corruption
mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to
23RIESGO
abrir ↗Exploit-DB
Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error
23RIESGO
abrir ↗Exploit-DB
SOL.Connect ISET-mpp meter 1.2.4.2 - SQL Injection
SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB
Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system
23RIESGO
abrir ↗Exploit-DB
Advantech SUSIAccess < 3.0 - Directory Traversal / Information Disclosure (Metasploit)
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - 'xpc_data' Objects Sandbox Escape Privilege Escalation
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service
23RIESGO
abrir ↗Exploit-DB
libao 1.2.0 - Denial of Service
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of servic
23RIESGO
abrir ↗Exploit-DB
DivFix++ 0.34 - Denial of Service
The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denia
23RIESGO
abrir ↗Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (div
23RIESGO
abrir ↗Exploit-DB
libvorbis 1.3.5 - Multiple Vulnerabilities
The vorbis_analysis_wrote function in lib/block.c in Xiph.Org libvorbis 1.3.5 allows remote attackers to cause a denial
23RIESGO
abrir ↗Metasploit0
Android Janus APK Signature bypass
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir ↗Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (d
23RIESGO
abrir ↗Exploit-DB
Vorbis Tools oggenc 1.4.0 - '.wav' Denial of Service
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of serv
23RIESGO
abrir ↗GitHub PoC★ 47
Exploit for Jenkins serialization vulnerability - CVE-2016-0792
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins < 1.650 - Java Deserialization
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RIESGO
abrir ↗Exploit-DB
McAfee Security Scan Plus - Remote Command Execution
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior
28RIESGO
abrir ↗GitHub PoC★ 1
ProFTPd 1.3.5 - File Copy
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir ↗Metasploit600
Western Digital MyCloud multi_uploadify File Upload Vulnerability
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquer
60RIESGO
abrir ↗GitHub PoC★ 53
Broadpwn bug (CVE-2017-9417)
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthor
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to exec
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthor
38RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.