Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
GitHub PoC★ 2
POC for java RMI deserialization vulnerability
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RIESGO
abrir ↗Exploit-DB
WordPress Plugin WatuPRO 5.5.1 - SQL Injection
SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitr
23RIESGO
abrir ↗GitHub PoC
VideoLAN VLC media player 0.9.4 Media Player ty.c buffer overflow
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir ↗Exploit-DB
Zookeeper 3.5.2 Client - Denial of Service
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper
45RIESGO
abrir ↗GitHub PoC★ 57
CVE-2017-0213 for command line
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir ↗VulnCheck XDB
initial-access
Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.
28RIESGO
abrir ↗VulnCheck XDB
local
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir ↗GitHub PoC
sUbc0ol/Microsoft-Word-CVE-2017-0199-
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir ↗GitHub PoC
sUbc0ol/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC★ 13
sUbc0ol/Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir ↗Exploit-DB
Odoo CRM 10.0 - Code Execution
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymi
23RIESGO
abrir ↗GitHub PoC
FreeSSHD Remote Authentication Bypass Vulnerability (freeSSHd 2.1.3)
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RIESGO
abrir ↗GitHub PoC
sUbc0ol/CVE-2015-0235
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir ↗VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗VulnCheck XDB
denial-of-service
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ActiveMQ < 5.14.0 - Web Shell Upload (Metasploit)
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir ↗GitHub PoC★ 1
CVE-2015-1635
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Veritas/Symantec Backup Exec - SSL NDMP Connection Use-After-Free (Metasploit)
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a u
60RIESGO
abrir ↗GitHub PoC
shaheemirza/CVE-2017-0213-
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
NetBSD - 'Stack Clash' (PoC)
NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attacke
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - 'setrlimit' Stack Clash (PoC)
In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only mem
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel (Debian 7.7/8.5/9.0 / Ubuntu 14.04.2/16.04.2/17.04 / Fedora 22/25 / CentOS 7.3.1611) - 'ldso_hwcap_64 Stack Clash' Local Privilege Escalation
The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities
In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the scriptNa
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Solaris 11.1/11.3 (RSH) - 'Stack Clash' Local Privilege Escalation
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Solaris 11.1/11.3 (RSH) - 'Stack Clash' Local Privilege Escalation
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir ↗GitHub PoC
qwertyuiop12138/CVE-2016-10033
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Solaris 11.1/11.3 (RSH) - 'Stack Clash' Local Privilege Escalation
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel - 'offset2lib' Stack Clash
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.