Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DB
DiskBoss Enterprise 8.5.12 - Denial of Service
CVE-2017-15665doswindows08 ene 2018
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack
23RIESGO
abrir
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-16886webappshardware08 ene 2018
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
23RIESGO
abrir
Exploit-DBVexDay Proof
Vanilla < 2.1.5 - Cross-Site Request Forgery
CVE-2017-1000432webappsphp08 ene 2018
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
23RIESGO
abrir
GitHub PoC1
OSX 10.13.2, CVE-2017-5753, Spectre, PoC, C, ASM for OSX, MAC, Intel Arch, Proof of Concept, Hopper.App Output
CVE-2017-5753MEDIUM07 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
VulnCheck XDB
local
CVE-2017-5753MEDIUM07 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC
Simply diff for CVE-2017-0785
CVE-2017-078507 ene 2018
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
VulnCheck XDB
local
CVE-2017-5753MEDIUM06 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC1
Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)
CVE-2017-5753MEDIUM06 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC7
The demo of the speculative execution attack Spectre (CVE-2017-5753, CVE-2017-5715).
CVE-2017-5753MEDIUM06 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows win32k - Using SetClassLong to Switch Between CS_CLASSDC and CS_OWNDC Corrupts DC Cache
CVE-2018-0744doswindows05 ene 2018
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
28RIESGO
abrir
Exploit-DB
gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
CVE-2017-17097webappsphp05 ene 2018
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords
23RIESGO
abrir
Exploit-DBVexDay Proof
Ayukov NFTP FTP Client 2.0 - Remote Buffer Overflow (Metasploit)
CVE-2017-15222remotewindows05 ene 2018
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RIESGO
abrir
GitHub PoC129
Oracle WebLogic WLS-WSAT Remote Code Execution Exploit (CVE-2017-10271)
CVE-2017-10271HIGHbajo ataqueransomware05 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
local
CVE-2012-4681CRITICALbajo ataqueransomware05 ene 2018
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RIESGO
abrir
GitHub PoC
A Simple PoC for CVE-2012-4681
CVE-2012-4681CRITICALbajo ataqueransomware05 ene 2018
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware05 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
CVE-2017-17098webappsphp05 ene 2018
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote a
23RIESGO
abrir
Exploit-DB
Gespage 7.4.8 - SQL Injection
CVE-2017-7997webappsjsp05 ene 2018
Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands
28RIESGO
abrir
Exploit-DB
Cisco IOS - Remote Code Execution
CVE-2017-6736HIGHbajo ataqueremotehardware05 ene 2018
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RIESGO
abrir
GitHub PoC12
2018年1月2日 (CVE-2017-5753 和 CVE-2017-5715) "幽灵" Spectre 漏洞利用
CVE-2017-5753MEDIUM05 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC4
Spectre (CVE-2017-5753) (CVE-2017-5715). Not By Me. Collected from Book.
CVE-2017-5753MEDIUM04 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC
specloli/CVE-2017-17692
CVE-2017-1769204 ene 2018
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
60RIESGO
abrir
Exploit-DBVexDay Proof
Xplico - Remote Code Execution (Metasploit)
CVE-2017-16666remotelinux04 ene 2018
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RIESGO
abrir
GitHub PoC771
Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715)
CVE-2017-5753MEDIUM04 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
Exploit-DB
Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)
CVE-2017-17411remotehardware04 ene 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-5753MEDIUM04 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure
CVE-2017-5715MEDIUMlocalmultiple03 ene 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure
CVE-2017-5753MEDIUMlocalmultiple03 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
GitHub PoC3
forked from https://github.com/s3xy/CVE-2017-10271. Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.Modified by hanc00l
CVE-2017-10271HIGHbajo ataqueransomware03 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware03 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
anteriorpágina 930 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.