Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.521GitHub PoC 15.321VulnCheck XDB 8970Nuclei 4394Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.184 exploits
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗Metasploit600
Microsoft Office Word Malicious Hta Execution
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Concrete5 CMS 8.1.0 - 'Host' Header Injection
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "ca
23RIESGO
abrir ↗GitHub PoC★ 12
SyFi/cve-2017-0199
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir ↗Metasploit600
Juju-run Agent Privilege Escalation
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate pe
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32kfull!SfnINLPUAHDRAWMENUITEM' Stack Memory Disclosure
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and W
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Creative Cloud Desktop Application < 4.0.0.185 - Local Privilege Escalation
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions durin
28RIESGO
abrir ↗GitHub PoC
ryhanson/CVE-2017-0199
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Multiple 'NtGdiGetDIBitsInternal' System Call
A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides
23RIESGO
abrir ↗GitHub PoC
homjxi0e/cve-2017-7269
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir ↗Exploit-DB
Cisco Catalyst 2960 IOS 12.2(55)SE1 - 'ROCEM' Remote Code Execution
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir ↗Exploit-DB
Cisco Catalyst 2960 IOS 12.2(55)SE11 - 'ROCEM' Remote Code Execution
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xen - Broken Check in 'memory_exchange()' Permits PV Guest Breakout
An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit / Safari 10.0.3 (12602.4.8) - Synchronous Page Load Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit / Safari 10.0.3 (12602.4.8) - Universal Cross-Site Scripting via a Focus Event and a Link Element
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RIESGO
abrir ↗Exploit-DB
Brother MFC-J6520DW - Authentication Bypass / Password Change
On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'JSC::SymbolTableEntry::isWatchable' Heap Buffer Overflow
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'Document::adoptNode' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir ↗Exploit-DB
Proxifier for Mac 2.17/2.18 - Privesc Escalation
Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid progra
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'JSC::B3::Procedure::resetReachability' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir ↗Exploit-DB
Quest Privilege Manager 6.0.0 - Arbitrary File Write
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to wr
28RIESGO
abrir ↗GitHub PoC★ 4
Exploit for CVE-2017-6971 remote command execution in nfsen 1.3.7.
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RIESGO
abrir ↗Exploit-DB
Moxa MXview 2.8 - Denial of Service
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView
28RIESGO
abrir ↗Exploit-DB
Moxa MXview 2.8 - Private Key Disclosure
Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.
28RIESGO
abrir ↗VulnCheck XDB
initial-access
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir ↗Exploit-DB
Moxa MX AOPC-Server 1.5 - XML External Entity Injection
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.
23RIESGO
abrir ↗GitHub PoC★ 213
CVE-2017-3881 Cisco Catalyst Remote Code Execution PoC
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir ↗Metasploit600
Trend Micro Threat Discovery Appliance admin_sys_time.cgi Remote Command Execution
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in
40RIESGO
abrir ↗Metasploit600
Trend Micro Threat Discovery Appliance admin_sys_time.cgi Remote Command Execution
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows
40RIESGO
abrir ↗Metasploit300
Quest Privilege Manager pmmasterd Buffer Overflow
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full
50RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.