Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.476Referência 23.442GitHub PoC 15.312VulnCheck XDB 8970Nuclei 4393Metasploit 3502✓ solo verificadosrecientespopularesriesgo
80.095 exploits
GitHub PoC★ 535
CVE-2017-11882 from https://github.com/embedi/CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗GitHub PoC★ 98
This is a Metasploit module which exploits CVE-2017-11882 using the POC released here : https://embedi.com/blog/skeleton-closet-ms-office-vulnerability-you-didnt-know-about.
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗VulnCheck XDB
initial-access
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗VulnCheck XDB
local
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗Exploit-DB
Vonage VDV-23 - Denial of Service
On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or logi
23RIESGO
abrir ↗Exploit-DB
DblTek - Multiple Vulnerabilities
The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin pas
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - 'nt!NtQueryDirectoryFile (luafv!LuafvCopyDirectoryEntry)' Pool Memory Disclosure
Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2,
23RIESGO
abrir ↗GitHub PoC★ 22
CVE-2017-12149 JBOSS as 6.X反序列化(反弹shell版)
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir ↗Metasploit300
Clickjacking Vulnerability In CSRF Error Page pfSense
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged e
30RIESGO
abrir ↗GitHub PoC★ 331
CVE-2017-11882 Exploit accepts over 17k bytes long command/code in maximum.
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗GitHub PoC
CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗GitHub PoC★ 34
CVE-2017-11882 File Generator PoC
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
iOS < 11.1 / tvOS < 11.1 / watchOS < 4.1 - Denial of Service
An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS be
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 10 - CiSetFileCache TOCTOU Security Feature Bypass
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allow
23RIESGO
abrir ↗GitHub PoC★ 495
Proof-of-Concept exploits for CVE-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗Exploit-DB
Microsoft Office - OLE Remote Code Execution
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗VulnCheck XDB
client-side
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗VulnCheck XDB
infoleak
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗GitHub PoC★ 2
Exploits CVE-2016-10033 and CVE-2016-10045
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir ↗GitHub PoC★ 68
CVE-2017-8917 - SQL injection Vulnerability Exploit in Joomla 3.7.0
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir ↗GitHub PoC★ 3
zhouat/cve-2017-11882
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir ↗GitHub PoC★ 2
herbiezimmerman/2017-11-17-Maldoc-Using-CVE-2017-0199
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir ↗Exploit-DB
Icon Time Systems RTC-1000 Firmware 2.5.7458 - Cross-Site Scripting
A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows re
23RIESGO
abrir ↗Exploit-DB
LanSweeper 6.0.100.75 - Cross-Site Scripting
LanSweeper 6.0.100.75 has XSS via the description parameter to /Calendar/CalendarActions.aspx.
23RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Zeta Components Mail 1.8.1 - Remote Code Execution
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the s
28RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge - 'Object.setPrototypeOf' Memory Corruption
Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user
35RIESGO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Edge Chakra JIT - Type Confusion with switch Statements
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.