Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.460Referência 22.910GitHub PoC 14.997VulnCheck XDB 8843Nuclei 4358Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
ExaGrid - Known SSH Key and Default Password (Metasploit)
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - MSHTML!CSVGHelpers::SetAttributeStringAndPointer Use-After-Free (MS16-023)
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - URLStream.readObject Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - textfield.maxChars Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - 'NtGdiGetTextExtentExW' Out-of-Bounds Memory Read
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Color.setTransform Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Kernel - Bitmap Use-After-Free
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Jetspeed - Arbitrary File Upload (Metasploit)
Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Jetspeed - Arbitrary File Upload (Metasploit)
Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attacker
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime < 7.7.79.80.95 - '.FPX' Parsing Memory Corruption (2)
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (m
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime < 7.7.79.80.95 - '.PSD' Parsing Memory Corruption
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime < 7.7.79.80.95 - '.FPX' Parsing Memory Corruption (1)
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Object.unwatch Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Cogent Datahub 7.3.9 Gamma Script - Local Privilege Escalation
Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Zlib Codec Heap Overflow
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows an
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Use-After-Free and Double Delete Due to Incorrect Locking in Intel GPU Driver
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary co
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Uninitialized Stack Parameter Access in AsBroadcaster.broadcastMessage UaF Fix
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Uninitialized Stack Parameter Access in Object.unwatch UaF Fix
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Shape Rendering Crash
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Uninitialized Stack Parameter Access in MovieClip.swapDepths UaF Fix
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Flash - Sprite Creation Use-After-Free
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - AppleKeyStore Use-After-Free
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to exe
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Code Execution Due to Lack of Bounds Checking in AppleUSBPipe::Abort
IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a d
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX Kernel - Unchecked Array Index Used to Read Object Pointer Then Call Virtual Method in Nvidia Geforce Driver
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary c
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX / iOS - SUID Binary Logic Error Kernel Code Execution
Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 8.1/10 (x86) - Secondary Logon Standard Handles Missing Sanitization Privilege Escalation (MS16-032)
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Wildfly - 'WEB-INF' / 'META-INF' Information Disclosure via Filter Restriction Bypass
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD 10.2 (x64) - 'amd64_set_ldt' Heap Overflow
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TeamPass 2.1.24 - Multiple Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbi
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
TeamPass 2.1.24 - Multiple Vulnerabilities
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.