Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9001Nuclei 4401Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.324 exploits
Exploit-DB✓ VexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
35RIESGO
abrir ↗Exploit-DB
F5 BIG-IP 11.6 SSL Virtual Server - 'Ticketbleed' Memory Disclosure
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android - Inter-process munmap in android.util.MemoryIntArray
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
ntfs-3g - Unsanitized modprobe Environment Privilege Escalation
ntfs-3g: Modprobe influence vulnerability via environment variables
56RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android - android.util.MemoryIntArray Ashmem Race Conditions
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RIESGO
abrir ↗GitHub PoC★ 1
CVE-2017-2370
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir ↗Metasploit300
Kodi 17.0 Local File Inclusion Vulnerability
Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files v
40RIESGO
abrir ↗Exploit-DB
Linux Kernel 3.10.0 (CentOS 7) - Denial of Service
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RIESGO
abrir ↗GitHub PoC
CVE-2013-1775 Exploit written in Perl
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypas
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
28RIESGO
abrir ↗GitHub PoC
Minion plugin for checking Ticketbleed (CVE-2016-9244)
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RIESGO
abrir ↗GitHub PoC★ 30
This is a tool for exploiting Ticketbleed (CVE-2016-9244) vulnerability.
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RIESGO
abrir ↗Exploit-DB
F5 BIG-IP SSL Virtual Server - 'Ticketbleed' Memory Disclosure
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RIESGO
abrir ↗GitHub PoC★ 1
CVE-2016-9079 exploit code as it appeared on https://lists.torproject.org/pipermail/tor-talk/2016-November/042639.html
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir ↗Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RIESGO
abrir ↗VulnCheck XDB
client-side
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir ↗Exploit-DB
OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RIESGO
abrir ↗Metasploit600
Piwik Superuser Plugin Upload
Piwik Authenticated RCE via Custom Plugin Upload
43RIESGO
abrir ↗GitHub PoC★ 4
paralelo14/CVE-2015-1579
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir ↗Metasploit300
Postfixadmin Protected Alias Deletion Vulnerability
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected al
23RIESGO
abrir ↗Exploit-DB
CUPS < 2.0.3 - Remote Command Execution
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RIESGO
abrir ↗VulnCheck XDB
initial-access
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir ↗GitHub PoC★ 4
dmonst3r/CVE-2015-1579
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir ↗Exploit-DB
ntfs-3g (Debian 9) - Local Privilege Escalation
ntfs-3g: Modprobe influence vulnerability via environment variables
56RIESGO
abrir ↗GitHub PoC★ 5
Go Exploit for CVE-2011-4862
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RIESGO
abrir ↗GitHub PoC
Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2)
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir ↗VulnCheck XDB
initial-access
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'HTMLFormElement::reset()' Use-After Free
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebKit - 'HTMLKeygenElement' Type Confusion
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.