Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9001Nuclei 4401Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.324 exploits
Exploit-DB✓ VexDay Proof
Apple WebKit - Type Confusion in RenderBox with Accessibility Enabled
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir ↗Metasploit300
WordPress REST API Content Injection
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in Wor
40RIESGO
abrir ↗Metasploit600
AlienVault OSSIM/USM Remote Code Execution
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbit
50RIESGO
abrir ↗Exploit-DB
AlienVault OSSIM/USM < 5.3.1 - Remote Code Execution (Metasploit)
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vuln
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Netgear Routers - Password Disclosure
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RIESGO
abrir ↗Exploit-DB
PHP PEAR 1.10.1 - Arbitrary File Download
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenam
28RIESGO
abrir ↗GitHub PoC
OpenSSL CVE-2017-3730 proof-of-concept
Bad (EC)DHE parameters cause a client crash
35RIESGO
abrir ↗VulnCheck XDB
denial-of-service
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗GitHub PoC
CVE-2015-1635
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir ↗GitHub PoC
vagrant box exploiting cve-2016-0728
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir ↗Exploit-DB
Oracle VM VirtualBox < 5.0.32 / < 5.1.14 - Local Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions tha
23RIESGO
abrir ↗Exploit-DB
Radisys MRF - Command Injection
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RIESGO
abrir ↗Exploit-DB
OpenSSH 6.8 < 6.9 - 'PTY' Local Privilege Escalation
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial
23RIESGO
abrir ↗GitHub PoC
Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2) https://bugs.chromium.org/p/project-zero/issues/detail?id=1004
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB
OpenSSL 1.1.0 - Remote Client Denial of Service
Bad (EC)DHE parameters cause a client crash
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Palo Alto Networks Terminal Services Agent 7.0.3-13 - Integer Overflow
Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RIESGO
abrir ↗Metasploit600
Haraka SMTP Command Injection
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlie
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir ↗GitHub PoC★ 1
Proof of concept CVE-2016-2098
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir ↗Metasploit600
Oracle Weblogic Server Deserialization RCE - RMI UnicastRef
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir ↗GitHub PoC
Pilou-Pilou/docker_CVE-2014-6271.
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB
Systemd 228 (SUSE 12 SP2 / Ubuntu Touch 15.04) - Local Privilege Escalation
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd tim
23RIESGO
abrir ↗Metasploit300
Geutebrueck GCore - GCoreServer.exe Buffer Overflow RCE
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir ↗Exploit-DB
Geutebrueck GCore 1.3.8.42/1.4.2.37 - Remote Code Execution (Metasploit)
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle OpenJDK Runtime Environment 1.8.0_112-b15 - Java Serialization Denial Of Service
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RIESGO
abrir ↗Exploit-DB
NTOPNG 2.4 Web Interface - Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authenticati
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PageKit 1.0.10 - Password Reset
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the reg
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.