Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
Oracle Weblogic Server Deserialization RCE - Raw Object (Metasploit)
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Spidermonkey - IonMonkey Type Inference is Incorrect for Constructors Entered via OSR
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation 14.1.5 / VMware Player 15.0.2 - Host VMX Process Impersonation Hijack Privilege Escalation
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Manageme
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VMware Workstation 14.1.5 / VMware Player 15 - Host VMX Process COM Class Hijack Privilege Escalation
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft VBScript - VbsErase Memory Corruption
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome < M73 - Double-Destruction Race in StoragePartitionService
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome < M73 - MidiManagerWin Use-After-Free
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 11 - VBScript Execution Policy Bypass in MSHTML
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restri
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - Flash click2play Bypass with CObjectElement::FinalCreateObject
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash obj
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome < M73 - Data Race in ExtensionsGuestViewMessageFilter
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially explo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Google Chrome < M73 - FileSystemOperationRunner Use-After-Free
An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
BMC Patrol Agent - Privilege Escalation Code Execution Execution (Metasploit)
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for l
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CMS Made Simple Showtime2 Module 3.6.2 - (Authenticated) Arbitrary File Upload
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tika-server < 1.18 - Command Injection
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
elFinder PHP Connector < 2.1.48 - 'exiftran' Command Injection (Metasploit)
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD - Intel SYSRET Privilege Escalation (Metasploit)
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit)
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Android - getpidcon() Usage in Hardware binder ServiceManager Permits ACL Bypass
In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Android - binder Use-After-Free via racy Initialization of ->allow_user_free
In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux < 4.20.14 - Virtual Address 0 is Mappable via Privileged write() to /proc/*/mem
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
elFinder 2.1.47 - 'PHP connector' Command Injection
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux < 4.14.103 / < 4.19.25 - Out-of-Bounds Read and Write in SNMP NAT Module
In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Joomla! Component J2Store < 3.3.7 - SQL Injection
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation
Path traversal vulnerability in Filr web application
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nuuo Central Management - (Authenticated) SQL Server SQL Injection (Metasploit)
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WinRAR 5.61 - Path Traversal
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation
Local privilege escalation in Filr famtd
41RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.