Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
GitHub PoC2
Shadowshusky/CVE-2017-11882-
CVE-2017-11882HIGHbajo ataqueransomware27 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware27 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DB
Diving Log 6.0 - XML External Entity Injection
CVE-2017-9095localwindows27 nov 2017
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled d
23RIESGO
abrir
GitHub PoC2
CVE-2015-4852 Oracle WebLogic Scanner
CVE-2015-4852CRITICALbajo ataque25 nov 2017
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
GitHub PoC15
Exploit script for Apache Struts2 REST Plugin XStream RCE (‎CVE-2017-9805)
CVE-2017-9805HIGHbajo ataque24 nov 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
# CVE-2017-11882-metasploit This is a Metasploit module which exploits CVE-2017-11882 using the POC below: https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about. ## Installation 1) Copy the cve_2017_11882.rb to /usr/share/metasploit-framework/modules/exploits/windows/local/ 2) Copy the cve-2017-11882.rtf to /usr/share/metasploit-framework/data/exploits/ This module is a quick port to Metasploit and uses mshta.exe to execute the payload. There are better ways to implement this module and exploit but will update it as soon as I have the time.
CVE-2017-11882HIGHbajo ataqueransomware24 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9805HIGHbajo ataque24 nov 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC
CSC-pentest/cve-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware24 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel - 'mincore()' Uninitialized Kernel Heap Page Disclosure
CVE-2017-16994doslinux24 nov 2017
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque23 nov 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC3
Shellshock exploitation script that is able to upload and RCE using any vector due to its versatility.
CVE-2014-6271CRITICALbajo ataque23 nov 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
Linux Kernel (Ubuntu 17.04) - 'XFRM' Local Privilege Escalation
CVE-2017-16939locallinux23 nov 2017
The XFRM dump policy implementation in net/xfrm/xfrm_user.c in the Linux kernel before 4.13.11 allows local users to gai
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::SimpleLineLayout::RunResolver::runForPoint' Out-of-Bounds Read
CVE-2017-13784dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DB
KMPlayer 4.2.2.4 - Denial of Service
CVE-2017-16952doswindows22 nov 2017
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderText::localCaretRect' Out-of-Bounds Read
CVE-2017-13785dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
GitHub PoC
Grey-Li/CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware22 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DB
Winamp Pro 5.66.Build.3512 - Denial of Service
CVE-2017-16951doswindows22 nov 2017
Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, o
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::PositionIterator::decrement' Use-After-Free
CVE-2017-13797dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGPatternElement::collectPatternAttributes' Out-of-Bounds Read
CVE-2017-13783dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderObject::previousSibling' Use-After-Free
CVE-2017-13798dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
GitHub PoC
CVE-2017-9430 Fix
CVE-2017-943022 nov 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::DocumentLoader::frameLoader' Use-After-Free
CVE-2017-13794dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::InputType::element' Use-After-Free (2)
CVE-2017-13792dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::FormSubmission::create' Use-After-Free
CVE-2017-13791dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::AXObjectCache::performDeferredCacheUpdate' Use-After-Free
CVE-2017-13795dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-11882HIGHbajo ataqueransomware22 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware22 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::Style::TreeResolver::styleForElement' Use-After-Free
CVE-2017-13802dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::TreeScope::documentScope' Use-After-Free
CVE-2017-13796dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
GitHub PoC44
CVE-2017-11882 exploitation
CVE-2017-11882HIGHbajo ataqueransomware22 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
anteriorpágina 941 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.