Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Microsoft Windows - Running Object Table Register ROTFLAGS_ALLOWANYCLIENT Privilege Escalation
CVE-2017-0214doswindows17 may 2017
Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8/8.1/2012 R2 (x64) - 'EternalBlue' SMB Remote Code Execution (MS17-010)
CVE-2017-0144HIGHbajo ataqueransomwareremotewindows_x86-6417 may 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Quest Privilege Manager - pmmasterd Buffer Overflow (Metasploit)
CVE-2017-6553remotelinux15 may 2017
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - Uninitialized Memory in the Default dacl Descriptor of System Processes Token
CVE-2017-0258doswindows15 may 2017
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 Kernel - 'nt!NtTraceControl (EtwpSetProviderTraits)' Pool Memory Disclosure
CVE-2017-0259doswindows15 may 2017
The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - 'win32k!xxxClientLpkDrawTextEx' Stack Memory Disclosure
CVE-2017-0245doswindows15 may 2017
The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - Pool-Based Out-of-Bounds Reads Due to bind() Implementation Bugs in afd.sys / tcpip.sys
CVE-2017-0175doswindows15 may 2017
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sen
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - Pool-Based Out-of-Bounds Reads Due to bind() Implementation Bugs in afd.sys / tcpip.sys
CVE-2017-0220doswindows15 may 2017
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticat
23RIESGO
abrir
Exploit-DBVexDay Proof
Larson VizEx Reader 9.7.5 - Local Buffer Overflow (SEH)
CVE-2017-8927doswindows14 may 2017
Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified
23RIESGO
abrir
Exploit-DBVexDay Proof
Halliburton LogView Pro 10.0.1 - Local Buffer Overflow (SEH)
CVE-2017-8926doswindows14 may 2017
Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspeci
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.8.0-41-generic (Ubuntu) - Packet Socket Local Privilege Escalation
CVE-2017-7308locallinux11 may 2017
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RIESGO
abrir
Exploit-DBVexDay Proof
OpenVPN 2.4.0 - Denial of Service
CVE-2017-7478dosmultiple11 may 2017
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft IIS - WebDav 'ScStoragePathFromUrl' Remote Overflow (Metasploit)
CVE-2017-7269CRITICALbajo ataqueremotewindows11 may 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
Exploit-DBVexDay Proof
SAP SAPCAR 721.510 - Heap Buffer Overflow
CVE-2017-8852doslinux10 may 2017
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Security Essentials / SCEP (Microsoft Windows 8/8.1/10 / Windows Server) - 'MsMpEng' Remote Type Confusion
CVE-2017-0290remotewindows09 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
45RIESGO
abrir
Exploit-DBVexDay Proof
Gemalto SmartDiag Diagnosis Tool < 2.5 - Local Buffer Overflow (SEH)
CVE-2017-6953localwindows08 may 2017
Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card
23RIESGO
abrir
Exploit-DBVexDay Proof
MediaCoder 0.8.48.5888 - Local Buffer Overflow (SEH)
CVE-2017-8869localwindows08 may 2017
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari 10.0.3 - 'JSC::CachedCall' Use-After-Free
CVE-2017-2491remotemacos04 may 2017
Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remot
23RIESGO
abrir
Exploit-DBVexDay Proof
Ghostscript 9.21 - Type Confusion Arbitrary Command Execution (Metasploit)
CVE-2017-8291HIGHbajo ataquelocallinux02 may 2017
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir
Exploit-DBVexDay Proof
MySQL < 5.6.35 / < 5.7.17 - Integer Overflow
CVE-2017-3599dosmultiple01 may 2017
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RIESGO
abrir
Exploit-DBVexDay Proof
Tuleap Project Wiki 8.3 < 9.6.99.86 - Command Injection
CVE-2017-7981webappsphp01 may 2017
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project W
28RIESGO
abrir
Exploit-DBVexDay Proof
Admidio 3.2.8 - Cross-Site Request Forgery
CVE-2017-8382webappsphp28 abr 2017
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11.576.14393.0 - 'CStyleSheetArray::BuildListOfMatchedRules' Memory Corruption
CVE-2017-0202doswindows27 abr 2017
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
35RIESGO
abrir
Exploit-DBVexDay Proof
Realtek Audio Driver 6.0.1.7898 (Windows 10) - Dolby Audio X2 Service Privilege Escalation
CVE-2017-7293localwindows25 abr 2017
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Office Word - '.RTF' Malicious HTA Execution (Metasploit)
CVE-2017-0199HIGHbajo ataqueransomwareremotewindows25 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
Exploit-DBVexDay Proof
HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion
CVE-2017-5799webappsmultiple25 abr 2017
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP ve
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari - Array concat Memory Corruption
CVE-2017-2464dosmultiple25 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VirtualBox Guest Additions 5.1.18 - Unprivileged Windows User-Mode Guest Code Double-Free
CVE-2017-3587dosmultiple25 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder). Supported ve
23RIESGO
abrir
Exploit-DBVexDay Proof
HPE OpenCall Media Platform (OCMP) 4.3.2 - Cross-Site Scripting / Remote File Inclusion
CVE-2017-5798webappsmultiple25 abr 2017
A Remote Code Execution vulnerability in HPE OpenCall Media Platform (OCMP) was found. The vulnerability impacts OCMP ve
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 (Build 10586) - 'IEETWCollector' Arbitrary Directory/File Deletion Privilege Escalation
CVE-2017-0165localwindows20 abr 2017
An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.