Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.832GitHub PoC 14.991VulnCheck XDB 8829Nuclei 4357Metasploit 3489✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - Uninitialized Arguments (2)
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - 'EmitNew' Integer Overflow
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra - Incorrect JIT Optimization with TypedArray Setter #2
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge 38.14393.1066.0 - 'CInputDateTimeScrollerElement::_SelectValueInternal' Out-of-Bounds Read
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose in
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xamarin Studio for Mac 6.2.1 (build 3) / 6.3 (build 863) - Local Privilege Escalation
The Xamarin.iOS update component on systems running macOS allows an attacker to run arbitrary code as root, aka "Xamarin
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel < 4.4.0-83 / < 4.8.0-58 (Ubuntu 14.04/16.04) - Local Privilege Escalation (KASLR / SMEP)
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge 38.14393.1066.0 - 'textarea.defaultValue' Memory Disclosure
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose in
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Messaging Gateway < 10.6.3-267 - Cross-Site Request Forgery
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allo
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unitrends UEB 9.1 - 'Unitrends bpserverd' Remote Command Execution
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-296
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unitrends UEB 9.1 - Privilege Escalation
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR env
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 all
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remot
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Unitrends UEB 9.1 - Authentication Bypass / Remote Command Execution
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VirtualBox 5.1.22 - Windows Process DLL UNC Path Signature Bypass Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
VirtualBox 5.1.22 - Windows Process DLL Signature Bypass Privilege Escalation
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Nitro Pro PDF Reader 11.0.3.173 - Javascript API Code Execution (Metasploit)
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory tra
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple macOS/iOS - 'xpc_data' Objects Sandbox Escape Privilege Escalation
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Jenkins < 1.650 - Java Deserialization
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to ex
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to exec
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthor
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthor
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU libiberty - Buffer Overflow
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
AudioCoder 0.8.46 - Local Buffer Overflow (SEH)
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'JSArray::appendMemcpy' Uninitialized Memory Copy
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'ArgumentsEliminationPhase::transform' Incorrect LoadVarargs Handling
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
WebKit JSC - 'DFG::ByteCodeParser::flush(InlineStackEntry* inlineStackEntry)' Incorrect Scope Register Handling
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.