Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Type Confusion with switch Statements
CVE-2017-11811doswindows16 nov 2017
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra: JIT - 'OP_Memset' Type Confusion
CVE-2017-11873doswindows16 nov 2017
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra: JIT - 'Lowerer::LowerBoundCheck' Incorrect Integer Overflow Check
CVE-2017-11861doswindows16 nov 2017
Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker t
35RIESGO
abrir
Metasploit0
Microsoft Office CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware15 nov 2017
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DB
CommuniGatePro 6.1.16 - Cross-Site Scripting
CVE-2017-16962webappsmultiple15 nov 2017
The WebMail components (Crystal, pronto, and pronto4) in CommuniGate Pro before 6.2.1 have stored XSS vulnerabilities vi
23RIESGO
abrir
Exploit-DB
PSFTPd Windows FTP Server 10.0.4 Build 729 - Log Injection / Use-After-Free
CVE-2017-15271doswindows14 nov 2017
A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be
23RIESGO
abrir
Metasploit500
Dup Scout Enterprise Login Buffer Overflow
CVE-2017-1369614 nov 2017
A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9
40RIESGO
abrir
Exploit-DBVexDay Proof
D-Link DIR-605L < 2.08 - Denial of Service
CVE-2017-9675doshardware14 nov 2017
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
28RIESGO
abrir
Exploit-DB
PSFTPd Windows FTP Server 10.0.4 Build 729 - Log Injection / Use-After-Free
CVE-2017-15270doswindows14 nov 2017
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) f
23RIESGO
abrir
Exploit-DB
Web Viewer 1.0.0.193 (Samsung SRN-1670D) - Unrestricted File Upload
CVE-2017-16524webappsphp13 nov 2017
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_u
50RIESGO
abrir
Exploit-DB
IKARUS anti.virus 2.16.7 - 'ntguard_x64' Local Privilege Escalation
CVE-2017-14961localwindows_x86-6413 nov 2017
In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating
23RIESGO
abrir
Exploit-DBVexDay Proof
Kirby CMS < 2.5.7 - Cross-Site Scripting
CVE-2017-16807webappsphp13 nov 2017
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exist
23RIESGO
abrir
GitHub PoC160
Chrome < 62 uxss exploit (CVE-2017-5124)
CVE-2017-512413 nov 2017
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject
23RIESGO
abrir
GitHub PoC
Python exploit for CVE-2017-16806
CVE-2017-1680613 nov 2017
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RIESGO
abrir
Exploit-DB
Ulterius Server < 1.9.5.0 - Directory Traversal
CVE-2017-16806remotewindows13 nov 2017
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RIESGO
abrir
Metasploit500
Linux BPF Sign Extension Local Privilege Escalation
CVE-2017-1699512 nov 2017
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
Metasploit600
Polycom Shell HDX Series Traceroute Command Execution
CVE-2025-34093HIGH12 nov 2017
Polycom HDX Series Telnet Command Injection via lan traceroute
36RIESGO
abrir
Exploit-DBVexDay Proof
MyBB 1.8.13 - Remote Code Execution
CVE-2017-16780webappsphp11 nov 2017
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration fi
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB 1.8.13 - Cross-Site Scripting
CVE-2017-16781webappsphp11 nov 2017
The installer in MyBB before 1.8.13 has XSS.
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Endpoint Protection 12.1 - Tamper-Protection Bypass
CVE-2017-6331localwindows10 nov 2017
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a
23RIESGO
abrir
Metasploit300
Roundcube TimeZone Authenticated File Disclosure
CVE-2017-16651HIGHbajo ataque09 nov 2017
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RIESGO
abrir
Exploit-DBVexDay Proof
PHP 7.1.8 - Heap Buffer Overflow
CVE-2017-16642dosmultiple09 nov 2017
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian hand
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - 'jscript!JsErrorToString' Use-After-Free
CVE-2017-11810doswindows09 nov 2017
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Window
35RIESGO
abrir
GitHub PoC1
Fork of github.com/spring-projects/spring-data-rest (vulnerable to CVE-2017-8046)
CVE-2017-804608 nov 2017
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
Metasploit600
Synology DiskStation Manager smart.cgi Remote Command Execution
CVE-2017-1588908 nov 2017
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RIESGO
abrir
Metasploit300
Samsung Internet Browser SOP Bypass
CVE-2017-1769208 nov 2017
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
60RIESGO
abrir
Exploit-DB
Ametys CMS 4.0.2 - Password Reset
CVE-2017-16935webappsphp07 nov 2017
Ametys before 4.0.3 requires authentication only for URIs containing a /cms/ substring, which allows remote attackers to
23RIESGO
abrir
Exploit-DB
ManageEngine Applications Manager 13 - SQL Injection
CVE-2017-16543webappswindows07 nov 2017
Zoho ManageEngine Applications Manager 13 before build 13500 allows SQL injection via GraphicalView.do, as demonstrated
23RIESGO
abrir
Exploit-DB
ManageEngine Applications Manager 13 - SQL Injection
CVE-2017-16542webappswindows07 nov 2017
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name param
23RIESGO
abrir
Metasploit600
pfSense authenticated group member RCE
CVE-2016-1070906 nov 2017
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_
30RIESGO
abrir
anteriorpágina 943 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.