Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DB
Check_MK 1.2.8p25 - Information Disclosure
CVE-2017-14955webappspython18 oct 2017
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, whi
28RIESGO
abrir
Exploit-DBVexDay Proof
Xen - Pagetable De-typing Unbounded Recursion
CVE-2017-15595doslinux18 oct 2017
An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recu
23RIESGO
abrir
Exploit-DB
OpenText Documentum Content Server - Arbitrary File Download Privilege Escalation
CVE-2017-15012webappsmultiple17 oct 2017
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 does not properly validate the i
23RIESGO
abrir
Exploit-DB
OpenText Documentum Content Server - Arbitrary File Download
CVE-2017-15014webappsmultiple17 oct 2017
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design ga
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS 10.2 (14C92) - Remote Code Execution
CVE-2017-7115remoteios17 oct 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. The issue invo
23RIESGO
abrir
Exploit-DB
TP-Link WR940N - (Authenticated) Remote Code
CVE-2017-13772webappshardware17 oct 2017
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007)
CVE-2017-0037HIGHbajo ataqueremotewindows_x8617 oct 2017
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RIESGO
abrir
Exploit-DB
Linux Kernel - 'AF_PACKET' Use-After-Free (2)
CVE-2017-15649doslinux17 oct 2017
net/packet/af_packet.c in the Linux kernel before 4.13.6 allows local users to gain privileges via crafted system calls
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryObject (ObjectNameInformation)' Kernel Pool Memory Disclosure
CVE-2017-11785doswindows17 oct 2017
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Solr 7.0.1 - XML External Entity Expansion / Remote Code Execution
CVE-2017-12629webappsxml17 oct 2017
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction wi
60RIESGO
abrir
Exploit-DB
OpenText Documentum Content Server - 'dmr_content' Privilege Escalation
CVE-2017-15013webappsmultiple17 oct 2017
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design ga
23RIESGO
abrir
Exploit-DB
OpenText Documentum Content Server - Privilege Escalation
CVE-2017-15276webappsmultiple17 oct 2017
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design ga
23RIESGO
abrir
GitHub PoC
A simple python shell-like exploit for the Shellschok CVE-2014-6271 bug.
CVE-2014-6271CRITICALbajo ataque17 oct 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'StackScriptFunction::BoxState::Box' Accesses to Uninitialized Pointers (Denial of Service)
CVE-2017-11809doswindows17 oct 2017
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RIESGO
abrir
Exploit-DBVexDay Proof
Tomcat - Remote Code Execution via JSP Upload Bypass (Metasploit)
CVE-2017-12617HIGHbajo ataqueremotejava17 oct 2017
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Incorrect GenerateBailOut Calling Patterns
CVE-2017-11799doswindows17 oct 2017
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque17 oct 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - WLDP/MSHTML CLSID UMCI Bypass
CVE-2017-11823doswindows17 oct 2017
The Microsoft Device Guard on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'RegexHelper::StringReplace' Must Call the Callback Function with Updating ImplicitCallFlags
CVE-2017-11802doswindows17 oct 2017
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RIESGO
abrir
GitHub PoC
PHPMailer < 5.2.18 Remote Code Execution
CVE-2016-1003417 oct 2017
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 (Windows 7 x86) - 'mshtml.dll' Remote Code Execution (MS17-007)
CVE-2017-0059MEDIUMbajo ataqueremotewindows_x8617 oct 2017
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via
75RIESGO
abrir
Exploit-DB
Linux Kernel < 3.16.39 (Debian 8 x64) - 'inotfiy' Local Privilege Escalation
CVE-2017-7533locallinux_x86-6416 oct 2017
Race condition in the fsnotify implementation in the Linux kernel through 4.12.4 allows local users to gain privileges o
23RIESGO
abrir
Exploit-DB
3CX Phone System 15.5.3554.1 - Directory Traversal
CVE-2017-15359webappslinux16 oct 2017
In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory t
23RIESGO
abrir
Exploit-DB
Ikraus Anti Virus 2.16.7 - Remote Code Execution
CVE-2017-15643remotewindows16 oct 2017
An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKA
23RIESGO
abrir
Exploit-DB
Webmin 1.850 - Multiple Vulnerabilities
CVE-2017-15644webappscgi15 oct 2017
SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/h
23RIESGO
abrir
Exploit-DB
Webmin 1.850 - Multiple Vulnerabilities
CVE-2017-15645webappscgi15 oct 2017
CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker
23RIESGO
abrir
Exploit-DB
Webmin 1.850 - Multiple Vulnerabilities
CVE-2017-15646webappscgi15 oct 2017
Webmin before 1.860 has XSS with resultant remote code execution. Under the 'Others/File Manager' menu, there is a 'Down
23RIESGO
abrir
Exploit-DB
Logitech Media Server - Cross-Site Scripting
CVE-2017-15687webappsmultiple14 oct 2017
DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1
23RIESGO
abrir
Exploit-DB
phpMyFAQ 2.9.8 - Cross-Site Scripting (2)
CVE-2017-14619webappsphp13 oct 2017
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir
Exploit-DB
AlienVault Unified Security Management (USM) 5.4.2 - Cross-Site Request Forgery
CVE-2017-14956webappsphp13 oct 2017
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/
23RIESGO
abrir
anteriorpágina 947 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.