Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.954exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.987VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
OpenSSH 2.3 < 7.7 - Username Enumeration
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Parameter Scope Parsing Type Confusion
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - InitializeNumberFormat and InitializeDateTimeFormat Type Confusion
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
93RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - 'DictionaryPropertyDescriptor::CopyFrom' Type Confusion
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - ImplicitCallFlags Check Bypass with Intl
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH 2.3 < 7.7 - Username Enumeration (PoC)
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit)
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Weblogic Server - Deserialization Remote Code Execution (Metasploit)
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Android - Directory Traversal over USB via Injection in blkid Output
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerabili
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiClient 5.2.3 (Windows 10 x64 Creators) - Local Privilege Escalation
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiClient 5.2.3 (Windows 10 x64 Creators) - Local Privilege Escalation
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel - UDP Fragmentation Offset 'UFO' Privilege Escalation (Metasploit)
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
fusermount - user_allow_other Restriction Bypass and SELinux Label Control
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is act
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
SoftNAS Cloud < 4.0.3 - OS Command Injection
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Skia - Heap Overflow in SkScan::FillPath due to Precision Error
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux - BPF Sign Extension Local Privilege Escalation (Metasploit)
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nanopool Claymore Dual Miner - APIs Remote Code Execution (Metasploit)
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux (Ubuntu) - Other Users coredumps Can Be Read via setgid Directory and killpriv Bypass
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.