Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
24.695 exploits
Exploit-DB✓ VexDay Proof
piSignage 2.6.4 - Directory Traversal
The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
nostromo 1.9.6 - Remote Code Execution
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD - Dynamic Loader chpass Privilege Escalation (Metasploit)
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD-SA-19:02.fd - Privilege Escalation
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Django < 3.0 < 2.2 < 1.11 - Account Hijack
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenMRS - Java Deserialization RCE (Metasploit)
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 6.x - Dynamic Loader Privilege Escalation
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Linux 5.3 - Privilege Escalation via io_uring Offload of sendmsg() onto Kernel Thread with Kernel Creds
In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC - Heap-Based Memory Corruption due to Malformed TTF Font
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Internet Explorer - Use-After-Free in JScript Arguments During toJSON Callback
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
Type confusion in shiftfs
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
Reference count underflow in shiftfs
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
Mishandling of file-system uid/gid with namespaces in shiftfs
33RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Ubuntu 19.10 - ubuntu-aufs-modified mmap_region() Breaks Refcounting in overlayfs/shiftfs Error Path
Reference counting error in overlayfs/shiftfs error path when used in conjuction with aufs
41RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Bludit - Directory Traversal Image File Upload (Metasploit)
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
FusionPBX - Operator Panel exec.php Command Execution (Metasploit)
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerabili
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Xorg X11 Server - Local Privilege Escalation (Metasploit)
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Pulse Secure VPN - Arbitrary Command Execution (Metasploit)
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
An out-of-bounds read was addressed with improved input validation.
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
rConfig - install Command Execution (Metasploit)
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.