Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Apple iOS < 10.3.1 - Kernel
CVE-2017-699726 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir
Exploit-DB
Apple iOS < 10.3.1 - Kernel
CVE-2017-699926 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir
Exploit-DB
Apple iOS < 10.3.1 - Kernel
CVE-2017-699626 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir
Exploit-DB
Apple iOS < 10.3.1 - Kernel
CVE-2017-699826 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir
Exploit-DB
Apple iOS < 10.3.1 - Kernel
CVE-2017-697926 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir
Exploit-DB
Apple iOS < 10.3.1 - Kernel
CVE-2017-699426 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir
Exploit-DB
Apple iOS < 10.3.1 - Kernel
CVE-2017-698926 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchO
23RIESGO
abrir
Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
CVE-2017-1295423 ago 2017
The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of
23RIESGO
abrir
Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
CVE-2017-1295323 ago 2017
The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial
23RIESGO
abrir
Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
CVE-2017-1295223 ago 2017
The LoadString function in helper.h in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL pointer d
23RIESGO
abrir
Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
CVE-2017-1295023 ago 2017
The gig::Region::Region function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of service (NULL p
23RIESGO
abrir
Exploit-DB
Wireless Repeater BE126 - Local File Inclusion
CVE-2017-877023 ago 2017
There is LFD (local file disclosure) on BE126 WIFI repeater 1.0 devices that allows attackers to read the entire filesys
28RIESGO
abrir
Exploit-DB
libgig 4.0.0 (LinuxSampler) - Multiple Vulnerabilities
CVE-2017-1295123 ago 2017
The gig::DimensionRegion::CreateVelocityTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a den
23RIESGO
abrir
Exploit-DB
Automated Logic WebCTRL 6.5 - Local Privilege Escalation
CVE-2017-964422 ago 2017
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan
23RIESGO
abrir
Exploit-DB
IBM OpenAdmin Tool - SOAP welcomeServer PHP Code Execution (Metasploit)
CVE-2017-109222 ago 2017
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RIESGO
abrir
Exploit-DB
Automated Logic WebCTRL 6.5 - Unrestricted File Upload / Remote Code Execution
CVE-2017-965022 ago 2017
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL
23RIESGO
abrir
Exploit-DB
Automated Logic WebCTRL 6.1 - Path Traversal / Arbitrary File Write
CVE-2017-964022 ago 2017
A Path Traversal issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web prior to 6.5;
23RIESGO
abrir
Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
CVE-2017-1297021 ago 2017
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authenticati
23RIESGO
abrir
Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
CVE-2017-1297121 ago 2017
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or
23RIESGO
abrir
Exploit-DB
PDF-XChange Viewer 2.5 Build 314.0 - Code Execution
CVE-2017-1305621 ago 2017
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code vi
23RIESGO
abrir
Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
CVE-2017-1296521 ago 2017
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa
28RIESGO
abrir
Exploit-DB
PHPMyWind 5.3 - Cross-Site Scripting
CVE-2017-1298421 ago 2017
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.
23RIESGO
abrir
Exploit-DB
WebKitGTK 2.1.2 (Ubuntu 14.04) - Heap based Buffer Overflow
CVE-2014-130319 ago 2017
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RIESGO
abrir
Exploit-DB
Apple macOS Sierra 10.12.1 - 'IOFireWireFamily' FireWire Port Denial of Service
CVE-2016-760819 ago 2017
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireF
23RIESGO
abrir
Exploit-DB
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
CVE-2017-6327HIGHbajo ataque18 ago 2017
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situ
83RIESGO
abrir
Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
CVE-2017-1278618 ago 2017
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW40
28RIESGO
abrir
Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
CVE-2017-1278518 ago 2017
The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on Novi
28RIESGO
abrir
Exploit-DB
QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities
CVE-2017-997818 ago 2017
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RIESGO
abrir
Exploit-DB
ZKTime Web Software 2.0 - Improper Access Restrictions
CVE-2017-1468018 ago 2017
ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a P
23RIESGO
abrir
Exploit-DB
Mozilla Firefox < 45.0 - 'nsHtml5TreeBuilder' Use-After-Free (EMET 5.52 Bypass)
CVE-2016-196018 ago 2017
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox
35RIESGO
abrir
anteriorpágina 126 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.