Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Zoom Linux Client 2.0.106600.0904 - Stack-Based Buffer Overflow (PoC)
CVE-2017-1504818 dic 2017
Stack-based buffer overflow in the ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 allows remote
28RIESGO
abrir
Exploit-DB
Western Digital MyCloud - 'multi_uploadify' File Upload (Metasploit)
CVE-2017-1756018 dic 2017
An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquer
60RIESGO
abrir
Exploit-DB
Zoom Linux Client 2.0.106600.0904 - Command Injection
CVE-2017-1504918 dic 2017
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when c
28RIESGO
abrir
Exploit-DB
Linux kernel < 4.10.15 - Race Condition Privilege Escalation
CVE-2017-1066115 dic 2017
Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denia
28RIESGO
abrir
Exploit-DB
Sync Breeze 10.2.12 - Denial of Service
CVE-2017-1708815 dic 2017
The Enterprise version of SyncBreeze 10.2.12 and earlier is affected by a Remote Denial of Service vulnerability. The we
23RIESGO
abrir
Exploit-DB
Linksys WVBR0 - 'User-Agent' Remote Command Injection
CVE-2017-1741114 dic 2017
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RIESGO
abrir
Exploit-DB
Piwigo 2.9.1 - 'cat_true' / 'cat_false' SQL Injection
CVE-2017-1068214 dic 2017
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitra
23RIESGO
abrir
Exploit-DB
Advantech WebAccess 8.2-2017.03.31 - Webvrpcs Service Opcode 80061 Stack Buffer Overflow (Metasploit)
CVE-2017-1401614 dic 2017
A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. The applicati
43RIESGO
abrir
Exploit-DB
Readymade Video Sharing Script 3.2 - HTML Injection
CVE-2017-1764914 dic 2017
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RIESGO
abrir
Exploit-DB
Palo Alto Networks Firewalls - Root Remote Code Execution
CVE-2017-15944CRITICALbajo ataque14 dic 2017
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
Exploit-DB
Paid To Read Script 2.0.5 - 'uid' / 'fnum' / 'fn' SQL Injection
CVE-2017-1765114 dic 2017
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum para
23RIESGO
abrir
Exploit-DB
FS Lynda Clone 1.0 - SQL Injection
CVE-2017-1764314 dic 2017
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RIESGO
abrir
Exploit-DB
Bus Booking Script 1.0 - 'txtname' SQL Injection
CVE-2017-1764514 dic 2017
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RIESGO
abrir
Exploit-DB
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
CVE-2017-100040913 dic 2017
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ
23RIESGO
abrir
Exploit-DB
vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion
CVE-2017-1767213 dic 2017
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file delet
28RIESGO
abrir
Exploit-DB
Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read
CVE-2017-1678713 dic 2017
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read
23RIESGO
abrir
Exploit-DB
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
CVE-2017-100040813 dic 2017
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RIESGO
abrir
Exploit-DB
Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
CVE-2017-1787113 dic 2017
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
23RIESGO
abrir
Exploit-DB
Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
CVE-2017-1787213 dic 2017
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RIESGO
abrir
Exploit-DB
Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
CVE-2017-1787012 dic 2017
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RIESGO
abrir
Exploit-DB
Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
CVE-2017-1387612 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DB
Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
CVE-2017-1384712 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RIESGO
abrir
Exploit-DB
Apple macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapriController::GetLinkConfig
CVE-2017-1387512 dic 2017
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RIESGO
abrir
Exploit-DB
Apple macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
CVE-2017-1386712 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DB
Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload
CVE-2017-1694912 dic 2017
An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper in
28RIESGO
abrir
Exploit-DB
Advanced World Database 2.0.5 - SQL Injection
CVE-2017-1764011 dic 2017
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
23RIESGO
abrir
Exploit-DB
Apple macOS/iOS - Kernel Double Free due to IOSurfaceRootUserClient not Respecting MIG Ownership Rules
CVE-2017-1386111 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RIESGO
abrir
Exploit-DB
MikroTik 6.40.5 ICMP - Denial of Service
CVE-2017-1753811 dic 2017
MikroTik v6.40.5 devices allow remote attackers to cause a denial of service via a flood of ICMP packets.
23RIESGO
abrir
Exploit-DB
Vanguard 1.4 - Arbitrary File Upload
CVE-2017-1787411 dic 2017
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product
23RIESGO
abrir
Exploit-DB
Resume Clone Script 2.0.5 - SQL Injection
CVE-2017-1764111 dic 2017
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir
anteriorpágina 112 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.