Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
Exploit-DB
Nitro Pro PDF - Multiple Vulnerabilities
Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX
23RIESGO
abrir ↗Exploit-DB
Linux Kernel - 'BadIRET' Local Privilege Escalation
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Razer Synapse 2.20.15.1104 - rzpnk.sys ZwOpenProcess (Metasploit)
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'WebCore::AccessibilityRenderObject::handleAriaExpandedChanged' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Metasploit600
Nitro Pro PDF Reader 11.0.3.173 Javascript API Remote Code Execution
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory tra
50RIESGO
abrir ↗GitHub PoC★ 66
ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir ↗Exploit-DB
vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit)
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir ↗GitHub PoC★ 1
liusec/WP-CVE-2016-10033
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Metasploit600
DotNetNuke Cookie Deserialization Remote Code Excecution
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code e
100RIESGO
abrir ↗Metasploit600
DotNetNuke Cookie Deserialization Remote Code Excecution
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
100RIESGO
abrir ↗Metasploit600
DotNetNuke Cookie Deserialization Remote Code Excecution
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue ex
100RIESGO
abrir ↗Metasploit600
DotNetNuke Cookie Deserialization Remote Code Excecution
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expect
50RIESGO
abrir ↗Metasploit600
DotNetNuke Cookie Deserialization Remote Code Excecution
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expect
50RIESGO
abrir ↗Metasploit600
Supervisor XML-RPC Authenticated Remote Code Execution
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir ↗Exploit-DB
Citrix CloudBridge - 'CAKEPHP' Cookie Command Injection
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as r
100RIESGO
abrir ↗GitHub PoC★ 8
CVE-2014-9322 (a.k.a BadIRET) proof of concept for Linux
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RIESGO
abrir ↗Exploit-DB
Netscaler SD-WAN 9.1.2.26.561201 - Command Injection (Metasploit)
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as r
100RIESGO
abrir ↗Exploit-DB
Sonicwall Secure Remote Access 8.1.0.2-14sv - Command Injection
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabi
28RIESGO
abrir ↗Exploit-DB
Oracle E-Business Suite 12.x - Server-Side Request Forgery
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: iHelp). Suppo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'IOCTL 0x120007 NsiGetParameter' nsiproxy/netio Pool Memory Disclosure
Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and
23RIESGO
abrir ↗Exploit-DB
PEGA Platform <= 7.2 ML0 - Missing Access Control / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in PEGA Platform 7.2 ML0 and earlier allow remote attackers to injec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11.1066.14393.0 - VBScript Arithmetic Functions Type Confusion
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server
35RIESGO
abrir ↗Exploit-DB
Barracuda Load Balancer Firmware < 6.0.1.006 - Remote Command Injection (Metasploit)
A remote command injection vulnerability exists in the Barracuda Load Balancer product line (confirmed on v5.4.0.004 (20
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Sophos Web Appliance 4.3.0.2 - 'trafficType' Remote Command Injection (Metasploit)
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports wa
28RIESGO
abrir ↗Exploit-DB
Hashicorp vagrant-vmware-fusion < 4.0.20 - Local Privilege Escalation
The sudo helper in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.21 allows local use
23RIESGO
abrir ↗Exploit-DB
PEGA Platform <= 7.2 ML0 - Missing Access Control / Cross-Site Scripting
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11.0.9600.18617 - 'CMarkup::DestroySplayTree' Memory Corruption
Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute
35RIESGO
abrir ↗GitHub PoC★ 339
An internet scanner for exploit CVE-2017-0144 (Eternal Blue) & CVE-2017-0145 (Eternal Romance)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗Exploit-DB
Geneko Routers - Path Traversal
Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticate
23RIESGO
abrir ↗Exploit-DB
Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.