Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
Exploit-DB
WordPress Plugin WP Jobs < 1.5 - SQL Injection
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware vSphere Data Protection 5.x/6.x - Java Deserialization
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of th
23RIESGO
abrir ↗Exploit-DB
libquicktime 1.2.4 - Denial of Service
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a deni
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS - Disk Arbitration Daemon Race Condition
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitra
23RIESGO
abrir ↗Exploit-DB
libquicktime 1.2.4 - Denial of Service
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of se
23RIESGO
abrir ↗Metasploit600
IPFire proxy.cgi RCE
IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a
30RIESGO
abrir ↗Exploit-DB
libcroco 0.6.12 - Denial of Service
The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial o
28RIESGO
abrir ↗Exploit-DB
nuevoMailer 6.0 - SQL Injection
SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗Exploit-DB
libquicktime 1.2.4 - Denial of Service
The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of
23RIESGO
abrir ↗Exploit-DB
libquicktime 1.2.4 - Denial of Service
The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NU
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.3 / iOS < 10.3.2 - Userspace Entitlement Checking Race Condition
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The
23RIESGO
abrir ↗Exploit-DB
libquicktime 1.2.4 - Denial of Service
The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (i
23RIESGO
abrir ↗Exploit-DB
libquicktime 1.2.4 - Denial of Service
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of se
23RIESGO
abrir ↗Exploit-DB
libquicktime 1.2.4 - Denial of Service
The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of serv
23RIESGO
abrir ↗GitHub PoC
homjxi0e/CVE-2017-2671
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock a
23RIESGO
abrir ↗VulnCheck XDB
info-leak
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir ↗GitHub PoC★ 1
Struts-RCE CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC
homjxi0e/CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the
23RIESGO
abrir ↗GitHub PoC
homjxi0e/CVE-2017-7472
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumptio
23RIESGO
abrir ↗GitHub PoC★ 6
own implementation of the CVE-2017-1000367 sudo privilege escalation vulnerability in python
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir ↗VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the el
23RIESGO
abrir ↗Exploit-DB
Net Monitor for Employees Pro < 5.3.4 - Unquoted Service Path Privilege Escalation
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its
23RIESGO
abrir ↗GitHub PoC
homjxi0e/CVE-2017-9430
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir ↗Exploit-DB
Craft CMS 2.6 - Cross-Site Scripting
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation 12 Pro - Denial of Service
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Succes
23RIESGO
abrir ↗Exploit-DB
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Artifex MuPDF - Null Pointer Dereference
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function i
28RIESGO
abrir ↗GitHub PoC
smancke/CVE-2017-5638
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.