Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
CVE-2017-1166408 ago 2017
The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
23RIESGO
abrir
Exploit-DB
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-1115208 ago 2017
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 all
28RIESGO
abrir
Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
CVE-2017-1166108 ago 2017
The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
28RIESGO
abrir
Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
CVE-2017-1166208 ago 2017
The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and appli
23RIESGO
abrir
Exploit-DB
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-1115408 ago 2017
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-296
28RIESGO
abrir
Exploit-DB
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-1115508 ago 2017
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remot
35RIESGO
abrir
Exploit-DB
VMware WorkStation 12.5.5 - Virtual Machine Escape
CVE-2017-490108 ago 2017
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 ha
28RIESGO
abrir
Exploit-DB
Unitrends UEB 9.1 - Authentication Bypass / Remote Command Execution
CVE-2017-1247808 ago 2017
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir
Exploit-DB
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-1115308 ago 2017
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allo
28RIESGO
abrir
Exploit-DB
Unitrends UEB 9.1 - 'Unitrends bpserverd' Remote Command Execution
CVE-2017-1247708 ago 2017
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RIESGO
abrir
Exploit-DB
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-1115108 ago 2017
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers
28RIESGO
abrir
Exploit-DB
Unitrends UEB 9.1 - Privilege Escalation
CVE-2017-1247908 ago 2017
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR env
28RIESGO
abrir
Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
CVE-2017-1166308 ago 2017
The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
23RIESGO
abrir
Exploit-DB
Microsoft Windows - '.LNK' Shortcut File Code Execution
CVE-2017-8464HIGHbajo ataque06 ago 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
Exploit-DB
Tiandy IP Cameras 5.56.17.120 - Sensitive Information Disclosure
CVE-2017-1523603 ago 2017
Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to
23RIESGO
abrir
Exploit-DB
VirtualBox 5.1.22 - Windows Process DLL Signature Bypass Privilege Escalation
CVE-2017-1020403 ago 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RIESGO
abrir
Exploit-DB
DNSTracer 1.9 - Local Buffer Overflow
CVE-2017-943003 ago 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
Exploit-DB
VirtualBox 5.1.22 - Windows Process DLL UNC Path Signature Bypass Privilege Escalation
CVE-2017-1012903 ago 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RIESGO
abrir
Exploit-DB
Technicolor TC7337 - 'SSID' Persistent Cross-Site Scripting
CVE-2017-1132003 ago 2017
Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker
23RIESGO
abrir
Exploit-DB
Horde Groupware 5.2.21 - Unauthorized File Download
CVE-2017-1523503 ago 2017
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication
23RIESGO
abrir
Exploit-DB
Nitro Pro PDF Reader 11.0.3.173 - Javascript API Code Execution (Metasploit)
CVE-2017-744202 ago 2017
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory tra
50RIESGO
abrir
Exploit-DB
libmad 0.15.1b - 'mp3' Memory Corruption
CVE-2017-1155201 ago 2017
mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to
23RIESGO
abrir
Exploit-DB
SOL.Connect ISET-mpp meter 1.2.4.2 - SQL Injection
CVE-2017-1149401 ago 2017
SQL injection vulnerability in SOL.Connect ISET-mpp meter 1.2.4.2 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
Exploit-DB
Advantech SUSIAccess < 3.0 - Directory Traversal / Information Disclosure (Metasploit)
CVE-2016-934901 ago 2017
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system
23RIESGO
abrir
Exploit-DB
Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload
CVE-2016-934901 ago 2017
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system
23RIESGO
abrir
Exploit-DB
Advantech SUSIAccess < 3.0 - 'RecoveryMgmt' File Upload
CVE-2016-935101 ago 2017
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error
23RIESGO
abrir
Exploit-DB
Apple macOS/iOS - 'xpc_data' Objects Sandbox Escape Privilege Escalation
CVE-2017-704701 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RIESGO
abrir
Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
CVE-2017-1133231 jul 2017
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (div
23RIESGO
abrir
Exploit-DB
Sound eXchange (SoX) 14.4.2 - Multiple Vulnerabilities
CVE-2017-1135931 jul 2017
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (d
23RIESGO
abrir
Exploit-DB
libao 1.2.0 - Denial of Service
CVE-2017-1154831 jul 2017
The _tokenize_matrix function in audio_out.c in Xiph.Org libao 1.2.0 allows remote attackers to cause a denial of servic
23RIESGO
abrir
anteriorpágina 128 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.