Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.614GitHub PoC 15.330VulnCheck XDB 9001Nuclei 4401Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.324 exploits
GitHub PoC★ 4
Joomla 1.5 - 3.4.5 Object Injection RCE X-Forwarded-For header
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RIESGO
abrir ↗Exploit-DB
Splunk 6.1.1 - 'Referer' Header Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML
23RIESGO
abrir ↗Metasploit400
Debian/Ubuntu ntfs-3g Local Privilege Escalation
ntfs-3g: Modprobe influence vulnerability via environment variables
56RIESGO
abrir ↗Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir ↗Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Atlassian Confluence < 5.10.6 - Persistent Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitra
23RIESGO
abrir ↗Exploit-DB
Firejail < 0.9.44.4 / < 0.9.38.8 LTS - Local Sandbox Escape
Firejail before 0.9.44.4 and 0.9.38.x LTS before 0.9.38.8 LTS does not consider the .Xauthority case during its attempt
23RIESGO
abrir ↗VulnCheck XDB
client-side
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir ↗GitHub PoC★ 140
Proof-of-Concept exploit for Edge bugs (CVE-2016-7200 & CVE-2016-7201)
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir ↗VulnCheck XDB
client-side
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RIESGO
abrir ↗GitHub PoC
Script to take advantage of CVE-2010-3847
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RIESGO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RIESGO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RIESGO
abrir ↗VulnCheck XDB
denial-of-service
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass
35RIESGO
abrir ↗Exploit-DB
Zend Framework / zend-mail < 2.4.11 - Remote Code Execution
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Android - get_user/put_user (Metasploit)
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RIESGO
abrir ↗GitHub PoC★ 8
Prevent PHP vulnerabilities similar to CVE-2016-10033 and CVE-2016-10045.
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Exploit-DB
PHPMailer < 5.2.18 - Remote Code Execution
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Exploit-DB
SwiftMailer < 5.4.5-DEV - Remote Code Execution
The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass
35RIESGO
abrir ↗Exploit-DB
SapLPD 7.40 - Denial of Service
SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long
23RIESGO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 - Remote Code Execution
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗Exploit-DB
PHPMailer < 5.2.20 - Remote Code Execution
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit)
20RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wampserver 3.0.6 - Insecure File Permissions Privilege Escalation
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYS
23RIESGO
abrir ↗GitHub PoC★ 407
PHPMailer < 5.2.18 Remote Code Execution exploit and vulnerable container
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗GitHub PoC★ 2
k0keoyo/CVE-2012-0003_eXP
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Shutter 0.93.1 - Code Execution
/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a cra
23RIESGO
abrir ↗Metasploit600
TrueOnline / ZyXEL P660HN-T v2 Router Authenticated Command Injection
The ZyXEL P660HN-T1A v2 TCLinux Fw #7.3.37.6 router distributed by TrueOnline has a command injection vulnerability in t
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.