Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
GitHub PoC
This is the Apache Struts CVE-2017-5638 struts 2 vulnerability. The same CVE that resulted in the equifax database breach.
CVE-2017-5638CRITICALbajo ataqueransomware30 oct 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
iTech Gigs Script 1.21 - SQL Injection
CVE-2017-15963webappsphp30 oct 2017
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser pa
23RIESGO
abrir
Exploit-DB
CmsLite 1.4 - 'S' SQL Injection
CVE-2017-15984webappsphp30 oct 2017
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
23RIESGO
abrir
Metasploit600
Xplico Remote Code Execution
CVE-2017-1666629 oct 2017
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RIESGO
abrir
Exploit-DB
PHP Melody 2.6.1 - SQL Injection
CVE-2017-15081webappsphp28 oct 2017
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
23RIESGO
abrir
GitHub PoC2
This exploit was written to study some concepts, enjoy!
CVE-2010-422128 oct 2017
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RIESGO
abrir
Exploit-DB
PHPMyFAQ 2.9.8 - Cross-Site Scripting (3)
CVE-2017-15727webappsphp28 oct 2017
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Request Forgery
CVE-2017-15730webappsphp27 oct 2017
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
23RIESGO
abrir
Exploit-DB
HitmanPro 3.7.15 Build 281 - Kernel Pool Overflow
CVE-2017-6008localwindows26 oct 2017
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in
23RIESGO
abrir
Exploit-DB
Watchdog Development Anti-Malware / Online Security Pro - NULL Pointer Dereference
CVE-2017-15920doswindows26 oct 2017
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer
23RIESGO
abrir
Exploit-DB
Watchdog Development Anti-Malware / Online Security Pro - NULL Pointer Dereference
CVE-2017-15921doswindows26 oct 2017
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer
23RIESGO
abrir
Exploit-DB
KeystoneJS 4.0.0-beta.5 - Cross-Site Scripting
CVE-2017-15878webappsnodejs25 oct 2017
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-be
23RIESGO
abrir
Exploit-DB
KeystoneJS 4.0.0-beta.5 - CSV Excel Macro Injection
CVE-2017-15879webappsnodejs25 oct 2017
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCS
23RIESGO
abrir
Exploit-DB
PHPMailer < 5.2.21 - Local File Disclosure
CVE-2017-5223webappsphp25 oct 2017
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML docume
23RIESGO
abrir
Exploit-DB
Mura CMS < 6.2 - Server-Side Request Forgery / XML External Entity Injection
CVE-2017-15639webappscfm24 oct 2017
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the
23RIESGO
abrir
GitHub PoC2
dewankpant/CVE-2017-16567
CVE-2017-1656724 oct 2017
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. T
23RIESGO
abrir
Exploit-DBVexDay Proof
Unitrends UEB 9 - http api/storage Remote Root (Metasploit)
CVE-2017-12478remotelinux_x8623 oct 2017
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir
Exploit-DB
K7 Total Security 15.1.0.305 - Device Driver Arbitrary Memory Read
CVE-2017-18019doswindows23 oct 2017
In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the
23RIESGO
abrir
Exploit-DBVexDay Proof
Unitrends UEB 9 - bpserverd Authentication Bypass Remote Command Execution (Metasploit)
CVE-2017-12477remotelinux_x8623 oct 2017
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RIESGO
abrir
Exploit-DBVexDay Proof
Kaltura < 13.2.0 - Remote Code Execution
CVE-2017-14143webappsphp23 oct 2017
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, wh
60RIESGO
abrir
Metasploit600
Tuleap 9.6 Second-Order PHP Object Injection
CVE-2017-741123 oct 2017
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentEl
50RIESGO
abrir
GitHub PoC
Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -
CVE-2017-548722 oct 2017
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
Exploit-DB
Linux Kernel 4.14.0-rc4+ - 'waitid()' Local Privilege Escalation
CVE-2017-5123locallinux22 oct 2017
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
Metasploit300
Ayukov NFTP FTP Client Buffer Overflow
CVE-2017-1522221 oct 2017
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RIESGO
abrir
Exploit-DBVexDay Proof
Ayukov NFTP FTP Client < 2.0 - Remote Buffer Overflow
CVE-2017-15222remotewindows21 oct 2017
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RIESGO
abrir
Exploit-DB
ArGoSoft Mini Mail Server 1.0.0.2 - Denial of Service
CVE-2017-15223doswindows21 oct 2017
Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU re
23RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox < 55 - Denial of Service
CVE-2017-7783dosmultiple20 oct 2017
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example
28RIESGO
abrir
GitHub PoC1
Dirty COW (CVE-2016-5195) Testing
CVE-2016-5195HIGHbajo ataque19 oct 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Metasploit600
Oracle WebLogic wls-wsat Component Deserialization RCE
CVE-2017-10271HIGHbajo ataqueransomware19 oct 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC
An exploit for Apache Struts CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware19 oct 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
anteriorpágina 946 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.