Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DB
FiberHome - Directory Traversal
CVE-2017-15647webappslinux13 oct 2017
On FiberHome routers, Directory Traversal exists in /cgi-bin/webproc via the getpage parameter in conjunction with a cra
43RIESGO
abrir
Exploit-DB
TP-Link TL-MR3220 - Cross-Site Scripting
CVE-2017-15291webappshardware12 oct 2017
Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows
23RIESGO
abrir
Exploit-DB
Dreambox Plugin BouquetEditor - Cross-Site Scripting
CVE-2017-15287webappshardware12 oct 2017
There is XSS in the BouquetEditor WebPlugin for Dream Multimedia Dreambox devices, as demonstrated by the "Name des Bouq
38RIESGO
abrir
Exploit-DB
OctoberCMS 1.0.425 (Build 425) - Cross-Site Scripting
CVE-2017-15284webappsphp12 oct 2017
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG fil
23RIESGO
abrir
GitHub PoC1
Ready to use, weaponized dirtycow (CVE-2016-5195)
CVE-2016-5195HIGHbajo ataque11 oct 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC1
Exploit Safari CVE-2017-7089
CVE-2017-708911 oct 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RIESGO
abrir
Exploit-DB
Trend Micro OfficeScan 11.0/XG (12.0) - Remote Code Execution (Metasploit)
CVE-2017-11394webappsphp11 oct 2017
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitr
50RIESGO
abrir
GitHub PoC
CVE-2010-3332 Oracle Padding Vulnerability in Microsoft ASP.NET
CVE-2010-333211 oct 2017
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Intern
35RIESGO
abrir
GitHub PoC1
Apache HTTP Server 2.4.23 vulnerability study (CVE-2016-8740)
CVE-2016-874011 oct 2017
The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2
45RIESGO
abrir
Exploit-DB
ASX to MP3 3.1.3.7 - '.m3u' Local Buffer Overflow
CVE-2017-15221localwindows11 oct 2017
ASX to MP3 converter 3.1.3.7.2010.11.05 has a buffer overflow via a crafted M3U file, a related issue to CVE-2009-1324.
23RIESGO
abrir
Exploit-DB
binutils 2.29.51.20170921 - 'read_1_byte' Heap Buffer Overflow
CVE-2017-14939doslinux10 oct 2017
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.
23RIESGO
abrir
Exploit-DB
PHP Melody 2.7.3 - Multiple Vulnerabilities
CVE-2017-15579webappsphp09 oct 2017
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.
23RIESGO
abrir
Exploit-DB
QNAP HelpDesk < 1.1.12 - SQL Injection
CVE-2017-13068webappsphp09 oct 2017
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (2)
CVE-2017-12617HIGHbajo ataquewebappsjsp09 oct 2017
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
Metasploit300
Easy Chat Server User Registeration Buffer Overflow (SEH)
CVE-2017-954409 oct 2017
There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1
23RIESGO
abrir
GitHub PoC138
Blueborne CVE-2017-0781 Android heap overflow vulnerability
CVE-2017-078109 oct 2017
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
Exploit-DB
PHP Melody 2.7.3 - Multiple Vulnerabilities
CVE-2017-15578webappsphp09 oct 2017
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
23RIESGO
abrir
Exploit-DB
VX Search Enterprise 10.1.12 - Remote Buffer Overflow
CVE-2017-15220remotewindows09 oct 2017
Flexense VX Search Enterprise 10.1.12 is vulnerable to a buffer overflow via an empty POST request to a long URI beginni
23RIESGO
abrir
Exploit-DB
ASX to MP3 converter < 3.1.3.7 - '.asx' Local Stack Overflow (DEP Bypass)
CVE-2017-15083localwindows08 oct 2017
20RIESGO
abrir
GitHub PoC27
CVE-2017-13868: Information leak of uninitialized kernel heap data in XNU.
CVE-2017-1386807 oct 2017
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DBVexDay Proof
PyroBatchFTP 3.17 - Buffer Overflow (SEH)
CVE-2017-15035doswindows07 oct 2017
EmTec PyroBatchFTP before 3.18 allows remote servers to cause a denial of service (application crash).
23RIESGO
abrir
Metasploit600
Trend Micro OfficeScan Remote Code Execution
CVE-2017-1139407 oct 2017
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitr
50RIESGO
abrir
Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
CVE-2017-789607 oct 2017
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.
18RIESGO
abrir
Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
CVE-2017-1139207 oct 2017
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote att
30RIESGO
abrir
Metasploit600
Trend Micro InterScan Messaging Security (Virtual Appliance) Remote Code Execution
CVE-2017-1139107 oct 2017
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote att
30RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware06 oct 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12617HIGHbajo ataque06 oct 2017
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
Exploit-DB
Microsoft Windows 10 RS2 (x64) - 'win32kfull!bFill' Pool Overflow
CVE-2016-3309HIGHbajo ataqueransomwarelocalwindows_x86-6406 oct 2017
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
76RIESGO
abrir
VulnCheck XDB
local
CVE-2016-3309HIGHbajo ataqueransomware06 oct 2017
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
76RIESGO
abrir
GitHub PoC53
Exploits for the win32kfull!bFill vulnerability on Win10 x64 RS2 using Bitmap or Palette techniques
CVE-2016-3309HIGHbajo ataqueransomware06 oct 2017
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
76RIESGO
abrir
anteriorpágina 948 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.