Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DBVexDay Proof
Perspective ICM Investigation & Case 5.1.1.16 - Privilege Escalation
CVE-2017-11319webappswindows05 dic 2017
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and c
23RIESGO
abrir
Exploit-DBVexDay Proof
Readymade Classifieds Script 1.0 - SQL Injection
CVE-2017-17111webappsphp05 dic 2017
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-detail
23RIESGO
abrir
Exploit-DBVexDay Proof
Techno Portfolio Management Panel - 'id' SQL Injection
CVE-2017-17110webappsphp05 dic 2017
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
23RIESGO
abrir
GitHub PoC21
Better Exploit Code For CVE 2017 9805 apache struts
CVE-2017-9805HIGHbajo ataque04 dic 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9805HIGHbajo ataque04 dic 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
chu1337/CVE-2017-1000117
CVE-2017-100011703 dic 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
Exploit-DB
Ruby < 2.2.8 / < 2.3.5 / < 2.4.2 / < 2.5.0-preview1 - 'NET::Ftp' Command Injection
CVE-2017-17405localruby02 dic 2017
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and p
45RIESGO
abrir
Exploit-DBVexDay Proof
MistServer 2.12 - Cross-Site Scripting
CVE-2017-16884webappsmultiple01 dic 2017
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir
Exploit-DB
Artica Web Proxy 3.06 - Remote Code Execution
CVE-2017-17055webappsphp01 dic 2017
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site
23RIESGO
abrir
GitHub PoC
giovannidispoto/CVE-2017-13872-Patch
CVE-2017-1387230 nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RIESGO
abrir
Exploit-DB
Linux Kernel - 'The Huge Dirty Cow' Overwriting The Huge Zero Page (1)
CVE-2017-1000405doslinux30 nov 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation (Metasploit)
CVE-2017-13872localmacos30 nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RIESGO
abrir
GitHub PoC200
A POC for the Huge Dirty Cow vulnerability (CVE-2017-1000405)
CVE-2017-100040529 nov 2017
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RIESGO
abrir
Exploit-DBVexDay Proof
HP iMC Plat 7.2 - Remote Code Execution (2)
CVE-2017-5816remotewindows29 nov 2017
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Metasploit600
Mac OS X Root Privilege Escalation
CVE-2017-1387229 nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RIESGO
abrir
Exploit-DBVexDay Proof
QEMU - NBD Server Long Export Name Stack Buffer Overflow
CVE-2017-15118HIGHdoslinux29 nov 2017
A stack-based buffer overflow vulnerability was found in NBD server implementation in qemu before 2.11 allowing a client
46RIESGO
abrir
GitHub PoC1
CVE-2017-9805 - Exploit
CVE-2017-9805HIGHbajo ataque28 nov 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC1
Tomcat 远程代码执行漏洞 Exploit
CVE-2017-12615HIGHbajo ataqueransomware28 nov 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware28 nov 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC210
CVE-2017-12149 jboss反序列化 可回显
CVE-2017-12149CRITICALbajo ataqueransomware28 nov 2017
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9805HIGHbajo ataque28 nov 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
Exploit-DBVexDay Proof
HP iMC Plat 7.2 - Remote Code Execution
CVE-2017-5817remotewindows28 nov 2017
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Exploit-DB
WordPress Plugin WooCommerce 2.0/3.0 - Directory Traversal
CVE-2017-17058HIGHwebappsphp28 nov 2017
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.13.1 (High Sierra) - 'Blank Root' Local Privilege Escalation
CVE-2017-13872localmacos28 nov 2017
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RIESGO
abrir
GitHub PoC2
Shadowshusky/CVE-2017-11882-
CVE-2017-11882HIGHbajo ataqueransomware27 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Incorrect Function Declaration Scope
CVE-2017-11870doswindows27 nov 2017
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'GlobOpt::OptTagChecks' Must Consider IsLoopPrePass Properly
CVE-2017-11840doswindows27 nov 2017
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'BailOutOnTaggedValue' Bailouts Type Confusion
CVE-2017-11839doswindows27 nov 2017
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows a
35RIESGO
abrir
Exploit-DBVexDay Proof
Exim 4.89 - 'BDAT' Denial of Service
CVE-2017-16944dosmultiple27 nov 2017
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial
35RIESGO
abrir
Exploit-DBVexDay Proof
ZTE ZXDSL 831CII - Improper Access Restrictions
CVE-2017-16953webappshardware27 nov 2017
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo
28RIESGO
abrir
anteriorpágina 940 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.