Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
VulnCheck XDB
local
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
76RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit / Safari 10.0.3(12602.4.8) - 'WebCore::FrameView::scheduleRelayout' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir ↗VulnCheck XDB
local
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir ↗Exploit-DB
Sophos Cyberoam - Cross-site scripting
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Soph
23RIESGO
abrir ↗GitHub PoC★ 181
Proof-of-Concept exploit for CVE-2017-7494(Samba RCE from a writable share)
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗GitHub PoC★ 21
k0keoyo/CVE-2015-2546-Exploit
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
76RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox < 53 - 'gfxTextRun' Out-of-Bounds Read
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitabl
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit / Safari 10.0.3(12602.4.8) - 'Editor::Command::execute' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit - 'FrameLoader::clear' Stealing Variables via Page Navigation
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir ↗GitHub PoC
homjxi0e/CVE-2017-7494
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox < 53 - 'ConvolvePixel' Memory Disclosure
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for other
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 3.5.0 - Remote Code Execution
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - 'TIKeyboardLayout initWithCoder:' NSKeyedArchiver Heap Corruption Due to Rounding Error
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - Memory Corruption Due to Bad Bounds Checking in NSCharacterSet Coding for NSKeyedUnarchiver
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS - Lack of Bounds Checking in HIServices Custom CFObject Serialization Local Privilege Escalation
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibili
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - NSUnarchiver Heap Corruption Due to Lack of Bounds Checking in [NSBuiltinCharacterSet initWithCoder:]
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS Kernel - Use-After-Free Due to Bad Locking in Unix Domain Socket File Descriptor Externalization
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - 'CAMediaTimingFunctionBuiltin' NSKeyedArchiver Memory Corruption Due to Lack of Bounds Checking
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimati
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS - '32-bit syscall exit' Kernel Register Leak
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RIESGO
abrir ↗Metasploit600
VMware Workstation ALSA Config File Local Privilege Escalation
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration fil
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS - 'stackshot' Raw Frame Pointers
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation for Linux 12.5.2 build-4638234 - ALSA Configuration Host Local Privilege Escalation
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration fil
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 4.11 - eBPF Verifier Log Leaks Lower Half of map Pointer
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PlaySMS 1.4 - 'import.php' Remote Code Execution
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RIESGO
abrir ↗GitHub PoC★ 3
Admidio 3.2.8 Cross-Site Request Forgery Assigned CVE Number: CVE-2017-8382
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RIESGO
abrir ↗Metasploit600
PlaySMS import.php Authenticated CSV File Upload Code Execution
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RIESGO
abrir ↗Metasploit600
PlaySMS sendfromfile.php Authenticated "Filename" Field Code Execution
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile
50RIESGO
abrir ↗Exploit-DB
Mantis Bug Tracker 1.3.10/2.3.0 - Cross-Site Request Forgery
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequen
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.