Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
Exploit-DB
Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
35RIESGO
abrir ↗Metasploit400
OrientDB 2.2.x Remote Code Execution
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which a
60RIESGO
abrir ↗Metasploit600
Evince CBT File Command Injection
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir ↗Exploit-DB
OrientDB - Code Execution
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which a
60RIESGO
abrir ↗Exploit-DB
Skype for Business 2016 - Cross-Site Scripting
A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted
28RIESGO
abrir ↗Exploit-DB
360 Total Security - Local Privilege Escalation
360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any di
23RIESGO
abrir ↗VulnCheck XDB
initial-access
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RIESGO
abrir ↗VulnCheck XDB
local
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir ↗VulnCheck XDB
local
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir ↗VulnCheck XDB
initial-access
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir ↗VulnCheck XDB
local
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection
NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt pa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execu
28RIESGO
abrir ↗Exploit-DB
DataTaker DT80 dEX 1.50.012 - Information Disclosure
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a d
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM < 5.3.6 - Local Privilege Escalation
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privil
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM 5.3.4 - Command Injection
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts 2.3.x Showcase - Remote Code Execution
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir ↗GitHub PoC★ 2
Apache struts struts 2 048, CVE-2017-9791.
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir ↗Exploit-DB
Yaws 1.91 - Remote File Disclosure
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: th
60RIESGO
abrir ↗Metasploit600
Apache Struts 2 Struts 1 Plugin Showcase OGNL Code Execution
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir ↗GitHub PoC★ 24
CVE-2014-1303 (WebKit Heap based BOF) proof of concept for Linux
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RIESGO
abrir ↗VulnCheck XDB
initial-access
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir ↗GitHub PoC★ 27
CVE-2017-9791
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LibTIFF - 'tif_jbig.c' Denial of Service
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LibTIFF - '_TIFFVGetField (tiffsplit)' Out-of-Bounds Read
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cau
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
LibTIFF - 'tif_dirwrite.c' Denial of Service
In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoAutoDial CE 3.3 - Authentication Bypass / Command Injection (Metasploit)
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arb
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GoAutoDial CE 3.3 - Authentication Bypass / Command Injection (Metasploit)
Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.