Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DB
Piwigo 2.9.1 - 'cat_true' / 'cat_false' SQL Injection
CVE-2017-10682webappsphp14 dic 2017
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Palo Alto Networks Firewalls - Root Remote Code Execution
CVE-2017-15944CRITICALbajo ataqueremotehardware14 dic 2017
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
Exploit-DB
Readymade Video Sharing Script 3.2 - HTML Injection
CVE-2017-17649webappsphp14 dic 2017
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Bus Booking Script 1.0 - 'txtname' SQL Injection
CVE-2017-17645webappsphp14 dic 2017
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component JEXTN Question And Answer 3.1.0 - SQL Injection
CVE-2017-17871webappsphp13 dic 2017
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
CVE-2017-1000408locallinux13 dic 2017
A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environme
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component JEXTN Video Gallery 3.0.5 - 'id' SQL Injection
CVE-2017-17872webappsphp13 dic 2017
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU C Library Dynamic Loader glibc ld.so - Memory Leak / Buffer Overflow
CVE-2017-1000409locallinux13 dic 2017
A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environ
23RIESGO
abrir
Exploit-DB
Meinberg LANTIME Web Configuration Utility 6.16.008 - Arbitrary File Read
CVE-2017-16787webappscgi13 dic 2017
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote attackers to read
23RIESGO
abrir
Metasploit600
Linksys WVBR0-25 User-Agent Command Execution
CVE-2017-1741113 dic 2017
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RIESGO
abrir
Exploit-DB
vBulletin 5.x - 'cacheTemplates' Remote Arbitrary File Deletion
CVE-2017-17672webappsmultiple13 dic 2017
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file delet
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple XNU Kernel - Memory Corruption due to Integer Overflow in __offsetof Usage in posix_spawn on 32-bit Platforms
CVE-2017-13876dosmultiple12 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Metasploit400
Commvault Communications Service (cvd) Command Injection
CVE-2017-1804412 dic 2017
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain mess
30RIESGO
abrir
Metasploit600
Apache Spark Unauthenticated Command Execution
CVE-2018-1177012 dic 2017
From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the su
50RIESGO
abrir
Exploit-DB
Accesspress Anonymous Post Pro < 3.2.0 - Arbitrary File Upload
CVE-2017-16949webappsphp12 dic 2017
An issue was discovered in the AccessKeys AccessPress Anonymous Post Pro plugin through 3.1.9 for WordPress. Improper in
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS - Kernel Code Execution due to Lack of Bounds Checking in AppleIntelCapriController::GetLinkConfig
CVE-2017-13875dosmacos12 dic 2017
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - Multiple Kernel Use-After-Frees due to Incorrect IOKit Object Lifetime Management in IOTimeSyncClockManagerUserClient
CVE-2017-13847dosmultiple12 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. The is
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - Kernel Double Free due to Incorrect API Usage in Flow Divert Socket Option Handling
CVE-2017-13867dosmultiple12 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component JBuildozer 1.4.1 - 'appid' SQL Injection
CVE-2017-17870webappsphp12 dic 2017
The JBuildozer extension 1.4.1 for Joomla! has SQL Injection via the appid parameter in an entriessearch action.
23RIESGO
abrir
Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (2)
CVE-2017-1000405doslinux11 dic 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RIESGO
abrir
Exploit-DBVexDay Proof
Resume Clone Script 2.0.5 - SQL Injection
CVE-2017-17641webappsphp11 dic 2017
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Vanguard 1.4 - SQL Injection
CVE-2017-17873webappsphp11 dic 2017
Vanguard Marketplace Digital Products PHP 1.4 has SQL Injection via the PATH_INFO to the /p URI.
23RIESGO
abrir
Exploit-DBVexDay Proof
Opensource Classified Ads Script 3.2 - SQL Injection
CVE-2017-17623webappsphp11 dic 2017
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
23RIESGO
abrir
Exploit-DB
Basic Job Site Script 2.0.5 - SQL Injection
CVE-2017-17642webappsphp11 dic 2017
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RIESGO
abrir
Exploit-DBVexDay Proof
Kickstarter Clone Acript 2.0 - 'projid' SQL Injection
CVE-2017-17618webappsphp11 dic 2017
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Laundry Booking Script 1.0 - 'list?city' SQL Injection
CVE-2017-17619webappsphp11 dic 2017
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
MLM Forced Matrix 2.0.9 - 'newid' SQL Injection
CVE-2017-17636webappsphp11 dic 2017
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Readymade Video Sharing Script 3.2 - SQL Injection
CVE-2017-17627webappsphp11 dic 2017
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Online Exam Test Application Script 1.6 - 'exams.php?sort' SQL Injection
CVE-2017-17622webappsphp11 dic 2017
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Professional Service Script 1.0 - 'service-list?city' SQL Injection
CVE-2017-17625webappsphp11 dic 2017
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
23RIESGO
abrir
anteriorpágina 936 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.