Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Microsoft Windows 10 (Build 10586) - 'IEETWCollector' Arbitrary Directory/File Deletion Privilege Escalation
CVE-2017-0165localwindows20 abr 2017
An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox 5.1.14 r112924 - Unprivileged Host User to Host Kernel Privilege Escalation via ALSA config
CVE-2017-3576locallinux20 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - Guest-to-Host Privilege Escalation via Broken Length Handling in slirp Copy
CVE-2017-3558localmultiple20 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Runtime Broker ClipboardBroker Privilege Escalation
CVE-2017-0211localwindows20 abr 2017
An elevation of privilege vulnerability exists in Windows 10, Windows 8.1, Windows RT 8.1, Windows Server 2012, Windows
28RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - Environment and ioctl Unprivileged Host User to Host Kernel Privilege Escalation
CVE-2017-3561dosmultiple20 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox 5.0.32 r112930 (x64) - Windows Process COM Injection Privilege Escalation
CVE-2017-3563localwindows_x86-6420 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle VM VirtualBox - 'virtio-net' Guest-to-Host Out-of-Bounds Write
CVE-2017-3575dosmultiple20 abr 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RIESGO
abrir
Exploit-DBVexDay Proof
Dmitry 1.3a - Local Buffer Overflow (PoC)
CVE-2017-7938MEDIUMdoslinux19 abr 2017
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau
33RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0145HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0143HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0147HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0146HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0144HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0148HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.3.0/2.3.0 - Password Reset
CVE-2017-7615webappsphp16 abr 2017
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RIESGO
abrir
Exploit-DBVexDay Proof
Concrete5 CMS 8.1.0 - 'Host' Header Injection
CVE-2017-7725webappsphp14 abr 2017
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "ca
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Multiple 'NtGdiGetDIBitsInternal' System Call
CVE-2017-0058doswindows13 abr 2017
A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32kfull!SfnINLPUAHDRAWMENUITEM' Stack Memory Disclosure
CVE-2017-0167doswindows13 abr 2017
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and W
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Creative Cloud Desktop Application < 4.0.0.185 - Local Privilege Escalation
CVE-2017-3006localwindows13 abr 2017
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions durin
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3 (12602.4.8) - Universal Cross-Site Scripting via a Focus Event and a Link Element
CVE-2017-2479webappsmultiple11 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RIESGO
abrir
Exploit-DBVexDay Proof
Xen - Broken Check in 'memory_exchange()' Permits PV Guest Breakout
CVE-2017-7228localmultiple11 abr 2017
An issue (known as XSA-212) was discovered in Xen, with fixes available for 4.8.x, 4.7.x, 4.6.x, 4.5.x, and 4.4.x. The e
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3 (12602.4.8) - Synchronous Page Load Universal Cross-Site Scripting
CVE-2017-2480webappsmultiple11 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'Document::adoptNode' Use-After-Free
CVE-2017-2468dosmultiple11 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'JSC::SymbolTableEntry::isWatchable' Heap Buffer Overflow
CVE-2017-2469dosmultiple11 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'JSC::B3::Procedure::resetReachability' Use-After-Free
CVE-2017-2470dosmultiple11 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6359webappscgi07 abr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands vi
28RIESGO
abrir
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6360webappscgi07 abr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information
35RIESGO
abrir
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6361webappscgi07 abr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
35RIESGO
abrir
Exploit-DBVexDay Proof
Faveo Helpdesk Community 1.9.3 - Cross-Site Request Forgery
CVE-2017-7571webappsphp05 abr 2017
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS Kernel 10.12.3 (16D32) - SIOCSIFORDER Socket ioctl Memory Corruption Due to Bad Bounds Checking
CVE-2017-2473dosmultiple04 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.