Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DB
Microsoft Windows 10 RS2 (x64) - 'win32kfull!bFill' Pool Overflow
CVE-2016-3309HIGHbajo ataqueransomwarelocalwindows_x86-6406 oct 2017
The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12617HIGHbajo ataque05 oct 2017
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC399
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution
CVE-2017-12617HIGHbajo ataque05 oct 2017
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'BytecodeGenerator::emitGetByVal' Incorrect Optimization (2)
CVE-2017-7117dosmultiple04 oct 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
28RIESGO
abrir
GitHub PoC31
Scan/Exploit Blueborne CVE-2017-0785
CVE-2017-078504 oct 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
Exploit-DB
EPESI 1.8.2 rev20170830 - Cross-Site Scripting
CVE-2017-14717webappsphp03 oct 2017
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.
23RIESGO
abrir
Exploit-DB
EPESI 1.8.2 rev20170830 - Cross-Site Scripting
CVE-2017-14712webappsphp03 oct 2017
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.
23RIESGO
abrir
Exploit-DB
Webkit (Safari) - Universal Cross-site Scripting
CVE-2017-7089localmultiple03 oct 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RIESGO
abrir
GitHub PoC63
Webkit uxss exploit (CVE-2017-7089)
CVE-2017-708903 oct 2017
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud befor
23RIESGO
abrir
Exploit-DB
Webkit (Chome < 61) - 'MHTML' Universal Cross-site Scripting
CVE-2017-5124localmultiple03 oct 2017
Incorrect application of sandboxing in Blink in Google Chrome prior to 62.0.3202.62 allowed a remote attacker to inject
23RIESGO
abrir
Metasploit600
Tomcat RCE via JSP Upload Bypass
CVE-2017-12617HIGHbajo ataque03 oct 2017
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
Metasploit600
HP Intelligent Management Java Deserialization RCE
CVE-2017-1255703 oct 2017
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and e
60RIESGO
abrir
VulnCheck XDB
local
CVE-2017-8464HIGHbajo ataque03 oct 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC
Usbhijacking | CVE-2017-8464
CVE-2017-8464HIGHbajo ataque03 oct 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
Exploit-DB
OpenText Document Sciences xPression 4.5SP1 Patch 13 - 'jobRunId' SQL Injection
CVE-2017-14757webappsjsp02 oct 2017
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b
23RIESGO
abrir
Exploit-DB
Linux Kernel < 4.14.rc3 - Local Denial of Service
CVE-2017-14489doslinux02 oct 2017
The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to
23RIESGO
abrir
Exploit-DB
OpenText Document Sciences xPression 4.5SP1 Patch 13 - 'documentId' SQL Injection
CVE-2017-14758webappsjsp02 oct 2017
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might b
23RIESGO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Heap Overflow
CVE-2017-14492dosmultiple02 oct 2017
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - 2-byte Heap Overflow
CVE-2017-14491dosmultiple02 oct 2017
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir
Exploit-DB
UCOPIA Wireless Appliance < 5.1.8 - Restricted Shell Escape
CVE-2017-11321locallinux02 oct 2017
The restricted shell interface in UCOPIA Wireless Appliance before 5.1.8 allows remote authenticated users to gain 'admi
23RIESGO
abrir
Exploit-DB
UCOPIA Wireless Appliance < 5.1.8 - Local Privilege Escalation
CVE-2017-11322locallinux02 oct 2017
The chroothole_client executable in UCOPIA Wireless Appliance before 5.1.8 allows remote attackers to gain root privileg
23RIESGO
abrir
Exploit-DB
phpCollab 2.5.1 - SQL Injection
CVE-2017-6089webappsphp02 oct 2017
SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
GitHub PoC3
this script is used for hack bluetooth devices CVE 2017 0785 which was done by ARMIS This File is password protected for password contact atusha@gmail.comr
CVE-2017-078502 oct 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
Exploit-DBVexDay Proof
Qmail SMTP - Bash Environment Variable Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotelinux02 oct 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Integer Underflow
CVE-2017-14496dosmultiple02 oct 2017
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-su
35RIESGO
abrir
Exploit-DBVexDay Proof
phpCollab 2.5.1 - Arbitrary File Upload
CVE-2017-6090webappsphp02 oct 2017
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RIESGO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Stack Overflow
CVE-2017-14493dosmultiple02 oct 2017
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RIESGO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Lack of free() Denial of Service
CVE-2017-14495dosmultiple02 oct 2017
Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote
45RIESGO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Information Leak
CVE-2017-14494dosmultiple02 oct 2017
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vect
35RIESGO
abrir
GitHub PoC
billa3283/CVE-2017-0213
CVE-2017-0213HIGHbajo ataqueransomware01 oct 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
anteriorpágina 949 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.