Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Perspective ICM Investigation & Case 5.1.1.16 - Privilege Escalation
CVE-2017-1131905 dic 2017
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and c
23RIESGO
abrir
Exploit-DB
Techno Portfolio Management Panel - 'id' SQL Injection
CVE-2017-1711005 dic 2017
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
23RIESGO
abrir
Exploit-DB
Ruby < 2.2.8 / < 2.3.5 / < 2.4.2 / < 2.5.0-preview1 - 'NET::Ftp' Command Injection
CVE-2017-1740502 dic 2017
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and p
45RIESGO
abrir
Exploit-DB
MistServer 2.12 - Cross-Site Scripting
CVE-2017-1688401 dic 2017
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir
Exploit-DB
Artica Web Proxy 3.06 - Remote Code Execution
CVE-2017-1705501 dic 2017
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site
23RIESGO
abrir
Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (1)
CVE-2017-100040530 nov 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RIESGO
abrir
Exploit-DB
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation (Metasploit)
CVE-2017-1387230 nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RIESGO
abrir
Exploit-DB
QEMU - NBD Server Long Export Name Stack Buffer Overflow
CVE-2017-15118HIGH29 nov 2017
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client
46RIESGO
abrir
Exploit-DB
HP iMC Plat 7.2 - Remote Code Execution (2)
CVE-2017-581629 nov 2017
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Exploit-DB
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation
CVE-2017-1387228 nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RIESGO
abrir
Exploit-DB
HP iMC Plat 7.2 - Remote Code Execution
CVE-2017-581728 nov 2017
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Exploit-DB
WordPress Plugin WooCommerce 2.0/3.0 - Directory Traversal
CVE-2017-17058HIGH28 nov 2017
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RIESGO
abrir
Exploit-DB
ZTE ZXDSL 831CII - Improper Access Restrictions
CVE-2017-1695327 nov 2017
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo
28RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - 'GlobOpt::OptTagChecks' Must Consider IsLoopPrePass Properly
CVE-2017-1184027 nov 2017
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - 'Inline::InlineCallApplyTarget_Shared' does not Return the return Instruction
CVE-2017-1184127 nov 2017
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RIESGO
abrir
Exploit-DB
Exim 4.89 - 'BDAT' Denial of Service
CVE-2017-1694427 nov 2017
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial
35RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Incorrect Function Declaration Scope
CVE-2017-1187027 nov 2017
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the
35RIESGO
abrir
Exploit-DB
Diving Log 6.0 - XML External Entity Injection
CVE-2017-909527 nov 2017
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled d
23RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - 'BailOutOnTaggedValue' Bailouts Type Confusion
CVE-2017-1183927 nov 2017
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows a
35RIESGO
abrir
Exploit-DB
Linux Kernel - 'mincore()' Uninitialized Kernel Heap Page Disclosure
CVE-2017-1699424 nov 2017
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RIESGO
abrir
Exploit-DB
Linux Kernel (Ubuntu 17.04) - 'XFRM' Local Privilege Escalation
CVE-2017-1693923 nov 2017
The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gai
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::RenderObject::previousSibling' Use-After-Free
CVE-2017-1379822 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::FormSubmission::create' Use-After-Free
CVE-2017-1379122 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::InputType::element' Use-After-Free (2)
CVE-2017-1379222 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DB
Winamp Pro 5.66.Build.3512 - Denial of Service
CVE-2017-1695122 nov 2017
Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, o
23RIESGO
abrir
Exploit-DB
KMPlayer 4.2.2.4 - Denial of Service
CVE-2017-1695222 nov 2017
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::SVGPatternElement::collectPatternAttributes' Out-of-Bounds Read
CVE-2017-1378322 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::SimpleLineLayout::RunResolver::runForPoint' Out-of-Bounds Read
CVE-2017-1378422 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::AXObjectCache::performDeferredCacheUpdate' Use-After-Free
CVE-2017-1379522 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::Style::TreeResolver::styleForElement' Use-After-Free
CVE-2017-1380222 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
anteriorpágina 116 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.