Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Microsoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007)
CVE-2017-0037HIGHbajo ataque17 oct 2017
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007)
CVE-2017-0059MEDIUMbajo ataque17 oct 2017
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via
75RIESGO
abrir
Exploit-DB
3CX Phone System 15.5.3554.1 - Directory Traversal
CVE-2017-1535916 oct 2017
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory t
23RIESGO
abrir
Exploit-DB
Linux Kernel < 3.16.39 (Debian 8 x64) - 'inotfiy' Local Privilege Escalation
CVE-2017-753316 oct 2017
Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges o
23RIESGO
abrir
Exploit-DB
Ikraus Anti Virus 2.16.7 - Remote Code Execution
CVE-2017-1564316 oct 2017
An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKA
23RIESGO
abrir
Exploit-DB
Webmin 1.850 - Multiple Vulnerabilities
CVE-2017-1564415 oct 2017
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/h
23RIESGO
abrir
Exploit-DB
Webmin 1.850 - Multiple Vulnerabilities
CVE-2017-1564615 oct 2017
Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Down
23RIESGO
abrir
Exploit-DB
Webmin 1.850 - Multiple Vulnerabilities
CVE-2017-1564515 oct 2017
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker
23RIESGO
abrir
Exploit-DB
Logitech Media Server - Cross-Site Scripting
CVE-2017-1568714 oct 2017
DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Scripting (2)
CVE-2017-1461913 oct 2017
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir
Exploit-DB
FiberHome - Directory Traversal
CVE-2017-1564713 oct 2017
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a cra
43RIESGO
abrir
Exploit-DB
AlienVault Unified Security Management (USM) 5.4.2 - Cross-Site Request Forgery
CVE-2017-1495613 oct 2017
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/
23RIESGO
abrir
Exploit-DB
Dreambox Plugin BouquetEditor - Cross-Site Scripting
CVE-2017-1528712 oct 2017
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouq
38RIESGO
abrir
Exploit-DB
TP-Link TL-MR3220 - Cross-Site Scripting
CVE-2017-1529112 oct 2017
Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows
23RIESGO
abrir
Exploit-DB
OctoberCMS 1.0.425 (Build 425) - Cross-Site Scripting
CVE-2017-1528412 oct 2017
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG fil
23RIESGO
abrir
Exploit-DB
ASX to MP3 3.1.3.7 - '.m3u' Local Buffer Overflow
CVE-2017-1522111 oct 2017
ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324.
23RIESGO
abrir
Exploit-DB
Trend Micro OfficeScan 11.0/XG (12.0) - Remote Code Execution (Metasploit)
CVE-2017-1139411 oct 2017
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitr
50RIESGO
abrir
Exploit-DB
binutils 2.29.51.20170921 - 'read_1_byte' Heap Buffer Overflow
CVE-2017-1493910 oct 2017
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.
23RIESGO
abrir
Exploit-DB
QNAP HelpDesk < 1.1.12 - SQL Injection
CVE-2017-1306809 oct 2017
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection
23RIESGO
abrir
Exploit-DB
PHP Melody 2.7.3 - Multiple Vulnerabilities
CVE-2017-1557809 oct 2017
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
23RIESGO
abrir
Exploit-DB
VX Search Enterprise 10.1.12 - Remote Buffer Overflow
CVE-2017-1522009 oct 2017
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginni
23RIESGO
abrir
Exploit-DB
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (2)
CVE-2017-12617HIGHbajo ataque09 oct 2017
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
Exploit-DB
PHP Melody 2.7.3 - Multiple Vulnerabilities
CVE-2017-1557909 oct 2017
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.
23RIESGO
abrir
Exploit-DB
PyroBatchFTP 3.17 - Buffer Overflow (SEH)
CVE-2017-1503507 oct 2017
EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).
23RIESGO
abrir
Exploit-DB
Microsoft Windows 10 RS2 (x64) - 'win32kfull!bFill' Pool Overflow
CVE-2016-3309HIGHbajo ataqueransomware06 oct 2017
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
76RIESGO
abrir
Exploit-DB
WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization (2)
CVE-2017-711704 oct 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RIESGO
abrir
Exploit-DB
Webkit (Safari) - Universal Cross-site Scripting
CVE-2017-708903 oct 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RIESGO
abrir
Exploit-DB
EPESI 1.8.2 rev20170830 - Cross-Site Scripting
CVE-2017-1471703 oct 2017
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
23RIESGO
abrir
Exploit-DB
EPESI 1.8.2 rev20170830 - Cross-Site Scripting
CVE-2017-1471203 oct 2017
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
23RIESGO
abrir
Exploit-DB
Webkit (Chome < 61) - 'MHTML' Universal Cross-site Scripting
CVE-2017-512403 oct 2017
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject
23RIESGO
abrir
anteriorpágina 121 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.