Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
19.066 exploits
Exploit-DB✓ VexDay Proof
Adobe Flash - LMZA Property Decoding Heap Corruption
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - ATF Image Packing Overflow
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 SP1 - 'mrxdav.sys' WebDAV Privilege Escalation (MS16-016) (Metasploit)
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - ATF Processing Overflow
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - JXR Processing Double-Free
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Wget < 1.18 - Arbitrary File Upload / Remote Code Execution
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ktools Photostore 4.7.5 - Blind SQL Injection
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - 'dec2lha Library' Remote Stack Buffer Overflow (PoC)
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
Multiple cross-site request forgery (CSRF) vulnerabilities in management scripts in Symantec Endpoint Protection Manager
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - PowerPoint Misaligned Stream-cache Remote Stack Buffer Overflow (PoC)
Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - TNEF Decoder Integer Overflow
Integer overflow in the TNEF unpacker in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); S
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - Heap Overflow Modifying MIME Messages
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - Missing Bounds Checks in dec2zip ALPkOldFormatDecompressor::UnShrink
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec AntiVirus - Unpacking RAR Multiple Remote Memory Corruptions
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'ATMFD.dll' NamedEscape 0x250C Pool Corruption (MS16-074)
atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wind
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple DIB-Related EMF Record Handlers Heap Out-of-Bounds Reads/Memory Disclosure (MS16-074)
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - Custom Font Disable Policy Bypass
The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted applica
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel - 'ecryptfs' '/proc/$pid/environ' Local Privilege Escalation
The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to ga
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 - win32k Bitmap Use-After-Free (MS16-062) (2)
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 7 - win32k Bitmap Use-After-Free (MS16-062) (1)
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Easy RM to MP3 Converter 2.7.3.700 - '.m3u' File (Universal ASLR + DEP Bypass)
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long fil
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in AppleMuxControl.kext
The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attack
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - NULL Dereference in IOAccelSharedUserClient2::page_off_resource
The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Use-After-Free Due to Bad Locking in IOAcceleratorFamily2
Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in AppleGraphicsDeviceControl
AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in IOAudioEngine
IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - NULL Dereference in CoreCaptureResponder Due to Unchecked Return Value
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.