Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DBVexDay Proof
FS Monster Clone 1.0 - 'Employer_Details.php?id' SQL Injection
CVE-2017-17585webappsphp08 dic 2017
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Thumbtack Clone 1.0 - 'cat' / 'sc' SQL Injection
CVE-2017-17589webappsphp08 dic 2017
FS Thumbtack Clone 1.0 has SQL Injection via the browse-category.php cat parameter or the browse-scategory.php sc parame
23RIESGO
abrir
Exploit-DBVexDay Proof
Website Auction Marketplace 2.0.5 - 'cat_id' SQL Injection
CVE-2017-17592webappsphp08 dic 2017
Website Auction Marketplace 2.0.5 has SQL Injection via the search.php cat_id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Shutterstock Clone 1.0 - 'keywords' SQL Injection
CVE-2017-17583webappsphp08 dic 2017
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.
23RIESGO
abrir
Exploit-DB
Doctor Search Script 1.0 - 'city' SQL Injection
CVE-2017-17611webappsphp08 dic 2017
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
GitHub PoC3
RTF Cleaner, tries to extract URL from malicious RTF samples using CVE-2017-0199 & CVE-2017-8759
CVE-2017-0199HIGHbajo ataqueransomware08 dic 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
Exploit-DB
CMS Auditor Website 1.0 - SQL Injection
CVE-2017-17607webappsphp08 dic 2017
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
23RIESGO
abrir
Exploit-DB
Nearbuy Clone Script 3.2 - 'search' SQL Injection
CVE-2017-17597webappsphp08 dic 2017
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.
23RIESGO
abrir
Exploit-DB
Chartered Accountant Booking Script 1.0 - 'city' SQL Injection
CVE-2017-17609webappsphp08 dic 2017
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Olx Clone 1.0 - 'scat' / 'pid' SQL Injection
CVE-2017-17586webappsphp08 dic 2017
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Quibids Clone 1.0 - SQL Injection
CVE-2017-17581webappsphp08 dic 2017
FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter.
23RIESGO
abrir
Exploit-DB
Co-work Space Search Script 1.0 - 'city' SQL Injection
CVE-2017-17606webappsphp08 dic 2017
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Exploit-DB
Entrepreneur Job Portal Script 2.0.6 - 'jobsearch_all.php?rid1' SQL Injection
CVE-2017-17596webappsphp08 dic 2017
Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
FS Stackoverflow Clone 1.0 - 'keywords' SQL Injection
CVE-2017-17590webappsphp08 dic 2017
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
23RIESGO
abrir
Exploit-DB
Child Care Script 1.0 - 'city' SQL Injection
CVE-2017-17608webappsphp08 dic 2017
Child Care Script 1.0 has SQL Injection via the /list city parameter.
23RIESGO
abrir
Exploit-DB
Apple macOS High Sierra 10.13 - 'ctl_ctloutput-leak' Information Leak
CVE-2017-13868localmacos07 dic 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 2.4.0 < 2.4.2 / 2.2.0 < 2.2.10 - CIP Safety Dissector Crash
CVE-2017-17085dosmultiple07 dic 2017
In Wireshark 2.4.0 to 2.4.2 and 2.2.0 to 2.2.10, the CIP Safety dissector could crash. This was addressed in epan/dissec
28RIESGO
abrir
Exploit-DB
Claymore Dual ETH + DCR/SC/LBC/PASC GPU Miner - Stack Buffer Overflow / Path Traversal
CVE-2017-16929remotewindows07 dic 2017
The remote management interface on the Claymore Dual GPU miner 10.1 is vulnerable to an authenticated directory traversa
28RIESGO
abrir
Exploit-DB
Claymore Dual ETH + DCR/SC/LBC/PASC GPU Miner - Stack Buffer Overflow / Path Traversal
CVE-2017-16930remotewindows07 dic 2017
The remote management interface on the Claymore Dual GPU miner 10.1 allows an unauthenticated remote attacker to execute
35RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.10.5 / < 4.14.3 (Ubuntu) - DCCP Socket Use-After-Free
CVE-2017-8824doslinux07 dic 2017
The dccp_disconnect function in net/dccp/proto.c in the Linux kernel through 4.14.3 allows local users to gain privilege
23RIESGO
abrir
Exploit-DBVexDay Proof
Arq 5.9.7 - Local Privilege Escalation
CVE-2017-16895localmacos06 dic 2017
The (1) arq_updater, (2) arqcommitter, (3) standardrestorer, (4) arqglacierrestorer, and (5) arqs3glacierrestorer helper
23RIESGO
abrir
GitHub PoC
acidburnmi/CVE-2016-5195-master
CVE-2016-5195HIGHbajo ataque06 dic 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
Hashicorp vagrant-vmware-fusion 5.0.1 - Local Privilege Escalation
CVE-2017-16001localmacos06 dic 2017
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.1, a local attacker or malware can silently su
23RIESGO
abrir
Exploit-DBVexDay Proof
Hashicorp vagrant-vmware-fusion 5.0.3 - Local Privilege Escalation
CVE-2017-16777localmacos06 dic 2017
If HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.3 is installed but VMware Fusion is not, a loc
23RIESGO
abrir
Exploit-DBVexDay Proof
Hashicorp vagrant-vmware-fusion 5.0.0 - Local Privilege Escalation
CVE-2017-15884localmacos06 dic 2017
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently su
23RIESGO
abrir
Exploit-DB
Sera 1.2 - Local Privilege Escalation / Password Disclosure
CVE-2017-15918localmacos06 dic 2017
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial
23RIESGO
abrir
Exploit-DB
Proxifier for Mac 2.19 - Local Privilege Escalation
CVE-2017-7690localmacos06 dic 2017
Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary w
23RIESGO
abrir
Exploit-DBVexDay Proof
Hashicorp vagrant-vmware-fusion 4.0.23 - Local Privilege Escalation
CVE-2017-11741localmacos06 dic 2017
HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo help
23RIESGO
abrir
Exploit-DBVexDay Proof
Arq 5.9.6 - Local Privilege Escalation
CVE-2017-15357localmacos06 dic 2017
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges v
23RIESGO
abrir
Exploit-DBVexDay Proof
Hashicorp vagrant-vmware-fusion 4.0.24 - Local Privilege Escalation
CVE-2017-12579localmacos06 dic 2017
An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and ear
23RIESGO
abrir
anteriorpágina 939 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.