Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.043exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.043 exploits
Exploit-DB
NetTransport 2.96L - Remote Buffer Overflow (DEP Bypass)
CVE-2017-17968remotewindows29 dic 2017
A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remot
50RIESGO
abrir
VulnCheck XDB
local
CVE-2017-1315629 dic 2017
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
GitHub PoC15
xyzAsian/Janus-CVE-2017-13156
CVE-2017-1315629 dic 2017
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
GitHub PoC29
CVE-2017-10271 POC
CVE-2017-10271HIGHbajo ataqueransomware28 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware28 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC143
WebLogic Exploit
CVE-2017-10271HIGHbajo ataqueransomware28 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware28 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
ALLMediaServer 0.95 - Remote Buffer Overflow (Metasploit)
CVE-2017-17932remotewindows28 dic 2017
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RIESGO
abrir
GitHub PoC1
CVE-2017-17562 GOAHEAD RCE (Author: Daniel Hodson)
CVE-2017-17562HIGHbajo ataque27 dic 2017
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-17562HIGHbajo ataque27 dic 2017
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
Exploit-DBVexDay Proof
SysGauge Server 3.6.18 - Denial of Service
CVE-2017-15667doswindows27 dic 2017
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafte
23RIESGO
abrir
Exploit-DB
ALLMediaServer 0.95 - Buffer Overflow (PoC)
CVE-2017-17932doswindows27 dic 2017
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RIESGO
abrir
Exploit-DB
Joomla! Component JEXTN FAQ Pro 4.0.0 - 'id' SQL Injection
CVE-2017-17875webappsphp26 dic 2017
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RIESGO
abrir
GitHub PoC3
CVE-2017-12615 Tomcat RCE (TESTED)
CVE-2017-12615HIGHbajo ataqueransomware26 dic 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware26 dic 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
Exploit-DB
Ubiquiti UniFi Video 3.7.3 - Local Privilege Escalation
CVE-2016-6914localwindows26 dic 2017
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RIESGO
abrir
Exploit-DB
Oracle WebLogic Server 10.3.6.0.0 / 12.x - Remote Command Execution
CVE-2017-10271HIGHbajo ataqueransomwareremotemultiple26 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
Biometric Shift Employee Management System 3.0 - Local File Disclosure
CVE-2017-17876webappsphp26 dic 2017
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a u
23RIESGO
abrir
Exploit-DB
GetGo Download Manager 5.3.0.2712 - Buffer Overflow
CVE-2017-17849doswindows26 dic 2017
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RIESGO
abrir
Exploit-DB
Trustwave SWG 11.8.0.27 - SSH Unauthorized Access
CVE-2017-18001remotelinux26 dic 2017
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the de
28RIESGO
abrir
GitHub PoC26
CVE-2017-17215 HuaWei Router RCE (NOT TESTED)
CVE-2017-1721525 dic 2017
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RIESGO
abrir
GitHub PoC3
Simplified PoC for Weblogic-CVE-2017-10271
CVE-2017-10271HIGHbajo ataqueransomware25 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
Huawei Router HG532 - Arbitrary Command Execution
CVE-2017-17215webappshardware25 dic 2017
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RIESGO
abrir
GitHub PoC22
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.
CVE-2017-10271HIGHbajo ataqueransomware25 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware25 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware23 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC39
CVE-2017-10271 WEBLOGIC RCE (TESTED)
CVE-2017-10271HIGHbajo ataqueransomware23 dic 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
Iopsys Router - 'dhcp' Remote Code Execution
CVE-2017-17867remotehardware23 dic 2017
Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying th
28RIESGO
abrir
GitHub PoC15
CVE-2017-12149 JBOSS RCE (TESTED)
CVE-2017-12149CRITICALbajo ataqueransomware22 dic 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware22 dic 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
anteriorpágina 932 / 2669siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.