Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.280exploits catalogados
37.122CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.609GitHub PoC 15.322VulnCheck XDB 8970Nuclei 4401Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.285 exploits
Exploit-DB
DIGISOL DG-HR1400 1.00.02 Wireless Router - Privilege Escalation
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from
23RIESGO
abrir ↗Exploit-DB
Oracle Knowledge Management 12.1.1 < 12.2.5 - XML External Entity Leading To Remote Code Execution
Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3
23RIESGO
abrir ↗Metasploit300
Cisco IOS Telnet Denial of Service
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir ↗Exploit-DB
Cisco IOS 12.2 < 12.4 / 15.0 < 15.6 - Security Association Negotiation Request Device Memory
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RIESGO
abrir ↗Metasploit600
SolarWinds LEM Default SSH Password Remote Code Execution
In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is acce
23RIESGO
abrir ↗VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC★ 3
Apache Struts (CVE-2017-5638) Shell
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB
AXIS (Multiple Products) - Cross-Site Request Forgery
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
23RIESGO
abrir ↗Exploit-DB
AXIS Communications - Cross-Site Scripting / Content Injection
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via v
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge 38.14393.0.0 - JavaScript Engine Use-After-Free
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
45RIESGO
abrir ↗GitHub PoC★ 2
Struts2 RCE CVE-2017-5638 non-intrusive check shell script
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB
Microsoft Windows DVD Maker 6.1.7 - XML External Entity Injection
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse cr
23RIESGO
abrir ↗Exploit-DB
WordPress Plugin Membership Simplified 1.58 - Arbitrary File Download
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membe
28RIESGO
abrir ↗Exploit-DB
Cerberus FTP Server 8.0.10.3 - 'MLST' Buffer Overflow (PoC)
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or p
28RIESGO
abrir ↗Exploit-DB
CommVault Edge 11 SP6 - Stack Buffer Overflow (PoC)
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack
28RIESGO
abrir ↗VulnCheck XDB
initial-access
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗GitHub PoC★ 83
MS16-032(CVE-2016-0099) for SERVICE ONLY
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - AVC Header Slicing Heap Overflow
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the F
28RIESGO
abrir ↗GitHub PoC★ 14
cve-2017-5638 Vulnerable site sample
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM WebSphere - RCE Java Deserialization (Metasploit)
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RIESGO
abrir ↗VulnCheck XDB
local
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir ↗Exploit-DB
Microsoft Windows - 'LoadUvsTable()' Heap Buffer Overflow
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - MovieClip Attach init Object Use-After-Free
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript
28RIESGO
abrir ↗Exploit-DB
Sitecore CMS 8.1 Update-3 - Cross-Site Scripting
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - 'Jakarta' Multipart Parser OGNL Injection (Metasploit)
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - ATF Planar Decompression Heap Overflow
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Te
28RIESGO
abrir ↗Metasploit600
Github Enterprise Default Session Secret And Deserialization Vulnerability
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated r
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - ATF Thumbnailing Heap Overflow
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture co
28RIESGO
abrir ↗Metasploit500
VX Search Enterprise GET Buffer Overflow
Buffer overflow in the web server service in VX Search Enterprise 10.0.14 allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.