Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
Exploit-DB✓ VexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthor
38RIESGO
abrir ↗GitHub PoC★ 1
搭建漏洞利用测试环境
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attack
23RIESGO
abrir ↗Exploit-DB
LAME 3.99.5 - Multiple Vulnerabilities
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of ser
23RIESGO
abrir ↗Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to
23RIESGO
abrir ↗Exploit-DB
libjpeg-turbo 1.5.1 - Denial of Service
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service
23RIESGO
abrir ↗GitHub PoC★ 55
CVE-2017-5689 Proof-of-Concept exploit
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU libiberty - Buffer Overflow
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary
23RIESGO
abrir ↗VulnCheck XDB
client-side
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AudioCoder 0.8.46 - Local Buffer Overflow (SEH)
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir ↗Exploit-DB
Microsoft Windows - '.LNK' Shortcut File Code Execution (Metasploit)
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'JSArray::appendMemcpy' Uninitialized Memory Copy
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'ArgumentsEliminationPhase::transform' Incorrect LoadVarargs Handling
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'DFG::ByteCodeParser::flush(InlineStackEntry* inlineStackEntry)' Incorrect Scope Register Handling
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗GitHub PoC★ 3
Exploit created by: R4v3nBl4ck end Pacman
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB
ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit)
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors invo
35RIESGO
abrir ↗VulnCheck XDB
remote-with-credentials
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB
Nitro Pro PDF - Multiple Vulnerabilities
Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX
23RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir ↗Exploit-DB
Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007)
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RIESGO
abrir ↗Exploit-DB
Linux Kernel - 'BadIRET' Local Privilege Escalation
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RIESGO
abrir ↗Metasploit600
Nitro Pro PDF Reader 11.0.3.173 Javascript API Remote Code Execution
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory tra
50RIESGO
abrir ↗GitHub PoC★ 66
ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir ↗Exploit-DB
vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit)
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::Node::getFlag' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderSearchField::addSearchResult' Heap Buffer Overflow
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::RenderObject' with Accessibility Enabled Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.