Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
osTicket 1.10 - SQL Injection (PoC)
CVE-2017-1439612 sep 2017
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a
23RIESGO
abrir
Exploit-DB
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (2)
CVE-2017-1434412 sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RIESGO
abrir
Exploit-DB
tcprewrite - Heap Buffer Overflow
CVE-2017-1426611 sep 2017
tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related
23RIESGO
abrir
Exploit-DB
Hanbanggaoke IP Camera - Arbitrary Password Change
CVE-2017-1433511 sep 2017
On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT requ
28RIESGO
abrir
Exploit-DB
Apache Struts 2.0.1 < 2.3.33 / 2.5 < 2.5.10 - Arbitrary Code Execution
CVE-2017-1261108 sep 2017
In Apache Struts 2.0.0 through 2.3.33 and 2.5 through 2.5.10.1, using an unintentional expression in a Freemarker tag in
60RIESGO
abrir
Exploit-DB
Roteador Wireless Intelbras WRN150 - Cross-Site Scripting
CVE-2017-1421907 sep 2017
XSS (persistent) on the Intelbras Wireless N 150Mbps router with firmware WRN 240 allows attackers to steal wireless cre
23RIESGO
abrir
Exploit-DB
McAfee LiveSafe 16.0.3 - Man In The Middle Registry Modification Leading to Remote Command Execution
CVE-2017-389807 sep 2017
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS)
23RIESGO
abrir
Exploit-DB
Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution
CVE-2017-9805HIGHbajo ataque06 sep 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
Exploit-DB
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Out-of-Bounds Write Privilege Escalation
CVE-2017-1407506 sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RIESGO
abrir
Exploit-DB
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (1)
CVE-2017-1415306 sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RIESGO
abrir
Exploit-DB
FiberHome ADSL AN1020-25 - Improper Access Restrictions
CVE-2017-1414705 sep 2017
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to ea
35RIESGO
abrir
Exploit-DB
Wireless Repeater BE126 - Remote Code Execution
CVE-2017-1371304 sep 2017
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user
23RIESGO
abrir
Exploit-DB
Mongoose Web Server 6.5 - Cross-Site Request Forgery / Remote Code Execution
CVE-2017-1156704 sep 2017
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the
23RIESGO
abrir
Exploit-DB
RubyGems < 2.6.13 - Arbitrary File Overwrite
CVE-2017-090104 sep 2017
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potenti
28RIESGO
abrir
Exploit-DB
CodeMeter 6.50 - Cross-Site Scripting
CVE-2017-1375404 sep 2017
Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter befor
23RIESGO
abrir
Exploit-DB
Lotus Notes Diagnostic Tool 8.5/9.0 - Local Privilege Escalation
CVE-2015-017902 sep 2017
Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users t
23RIESGO
abrir
Exploit-DB
IBM Notes 8.5.x/9.0.x - Denial of Service
CVE-2017-112902 sep 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RIESGO
abrir
Exploit-DB
WordPress Plugin Participants Database < 1.7.5.10 - Cross-Site Scripting
CVE-2017-1412601 sep 2017
The Participants Database plugin before 1.7.5.10 for WordPress has XSS.
23RIESGO
abrir
Exploit-DB
Motorola Bootloader - Kernel Cmdline Injection Secure Boot and Device Locking Bypass
CVE-2016-1027701 sep 2017
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RIESGO
abrir
Exploit-DB
OpenJPEG - 'mqc.c' Heap Buffer Overflow
CVE-2016-1050401 sep 2017
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote
23RIESGO
abrir
Exploit-DB
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.7 - SQL Injection
CVE-2016-100012531 ago 2017
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
23RIESGO
abrir
Exploit-DB
IBM Notes 8.5.x/9.0.x - Denial of Service (Metasploit)
CVE-2017-112931 ago 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RIESGO
abrir
Exploit-DB
Joomla! Component Huge-IT Video Gallery 1.0.9 - SQL Injection
CVE-2016-100012331 ago 2017
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
23RIESGO
abrir
Exploit-DB
Git < 2.7.5 - Command Injection (Metasploit)
CVE-2017-100011731 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
Exploit-DB
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.6 - SQL Injection
CVE-2016-100012431 ago 2017
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
23RIESGO
abrir
Exploit-DB
IBM Notes 8.5.x/9.0.x - Denial of Service (2)
CVE-2017-113031 ago 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it woul
43RIESGO
abrir
Exploit-DB
Oracle Java JDK/JRE < 1.8.0.131 / Apache Xerces 2.11.0 - 'PDF/Docx' Server Side Denial of Service
CVE-2017-1035530 ago 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supporte
28RIESGO
abrir
Exploit-DB
Metasploit Web UI < 4.14.1-20170828 - Cross-Site Request Forgery
CVE-2017-1508430 ago 2017
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
23RIESGO
abrir
Exploit-DB
D-Link DIR-600 - Authentication Bypass
CVE-2017-1294329 ago 2017
D-Link DIR-600 Rev Bx devices with v2.x firmware allow remote attackers to read passwords via a model/__show_info.php?RE
35RIESGO
abrir
Exploit-DB
Apple iOS < 10.3.1 - Kernel
CVE-2017-697926 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir
anteriorpágina 125 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.