Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
Qmail SMTP - Bash Environment Variable Injection (Metasploit)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - Heap Overflow
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Dnsmasq < 2.78 - 2-byte Heap Overflow
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Information Disclosure
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can acc
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Man In The Middle Remote Code Execution
A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to e
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Code Execution / Memory Corruption
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated u
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Private Key Disclosure
A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - 'Host' Header Injection
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Memory Read in MP4 Parsing
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Write in MP4 Edge Processing
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Out-of-Bounds Read in applyToRange
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation co
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple iOS 10.2 - Broadcom Out-of-Bounds Write when Handling 802.11k Neighbor Report Response
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Supervisor 3.0a1 < 3.3.2 - XML-RPC (Authenticated) Remote Code Execution (Metasploit)
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
CyberLink LabelPrint < 2.5 - Local Buffer Overflow (SEH Unicode)
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'Parser::ParseCatch' Does Not Handle 'eval()' (Denial of Service)
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'JavascriptFunction::ReparseAsmJsModule' Incorrectly Re-parses
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - Chakra Incorrectly Parses Object Patterns
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge 38.14393.1066.0 - Memory Corruption with Partial Page Loading
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge 38.14393.1066.0 - 'COptionsCollectionCacheItem::GetAt' Out-of-Bounds Read
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arb
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetFontResourceInfoInternalW' Stack Memory Disclosure
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k!NtQueryCompositionSurfaceBinding' Stack Memory Disclosure
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetGlyphOutline' Pool Memory Disclosure
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetPhysicalMonitorDescription' Stack Memory Disclosure
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiDoBanding' Stack Memory Disclosure
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'nt!NtSetIoCompletion / nt!NtRemoveIoCompletion' Pool Memory Disclosure
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k.sys' '.TTF' Font Processing Out-of-Bounds Reads/Writes with Malformed 'fpgm' table 'win32k!bGeneratePath' (Denial of Service)
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k.sys' '.TTF' Font Processing Out-of-Bounds Read with Malformed 'glyf' Table 'win32k!fsc_CalcGrayRow' (Denial of Service)
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiEngCreatePalette' Stack Memory Disclosure
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Infinite Automation Mango Automation - Command Injection (Metasploit)
Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execut
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.