Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DB
WordPress Plugin Hospital Management System - SQL Injection
CVE-2017-14846webappsphp26 sep 2017
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir
Exploit-DB
WordPress Plugin WPAMS - SQL Injection
CVE-2017-14847webappsphp26 sep 2017
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir
Exploit-DB
WordPress Plugin WPCHURCH - SQL Injection
CVE-2017-14845webappsphp26 sep 2017
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
23RIESGO
abrir
Exploit-DB
TicketPlus - Arbitrary File Upload
CVE-2017-14840webappsphp26 sep 2017
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
23RIESGO
abrir
Exploit-DB
Photo Fusion - Arbitrary File Upload
CVE-2017-14839webappsphp26 sep 2017
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS 10.2 - Broadcom Out-of-Bounds Write when Handling 802.11k Neighbor Report Response
CVE-2017-11120remoteios25 sep 2017
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RIESGO
abrir
Exploit-DB
Oracle 9i XDB 9.2.0.1 - HTTP PASS Buffer Overflow
CVE-2003-0727remotewindows25 sep 2017
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Read in applyToRange
CVE-2017-11282dosmultiple25 sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation co
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Memory Read in MP4 Parsing
CVE-2017-11281dosmultiple25 sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RIESGO
abrir
GitHub PoC
Check for Struts Vulnerability CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware25 sep 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware25 sep 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Write in MP4 Edge Processing
CVE-2017-11281dosmultiple25 sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RIESGO
abrir
Exploit-DBVexDay Proof
Supervisor 3.0a1 < 3.3.2 - XML-RPC (Authenticated) Remote Code Execution (Metasploit)
CVE-2017-11610remotelinux25 sep 2017
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir
GitHub PoC11
just a python script for cve-2017-12615
CVE-2017-12615HIGHbajo ataqueransomware25 sep 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-979824 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
GitHub PoC
l0n3rs/CVE-2017-9798
CVE-2017-979824 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
GitHub PoC
l0n3rs/CVE-2017-8759
CVE-2017-8759HIGHbajo ataque24 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
Metasploit300
Hikvision IP Camera Unauthenticated Password Change Via Improper Authentication Logic
CVE-2017-7921CRITICALbajo ataque23 sep 2017
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
Metasploit300
Unauthenticated information disclosure such as configuration, credentials and camera snapshots of a vulnerable Hikvision IP Camera
CVE-2017-7921CRITICALbajo ataque23 sep 2017
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
Metasploit300
CyberLink LabelPrint 2.5 Stack Buffer Overflow
CVE-2017-1462723 sep 2017
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RIESGO
abrir
GitHub PoC19
Blueborne CVE-2017-1000251 PoC for linux machines
CVE-2017-100025123 sep 2017
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RIESGO
abrir
Exploit-DBVexDay Proof
CyberLink LabelPrint < 2.5 - Local Buffer Overflow (SEH Unicode)
CVE-2017-14627localwindows23 sep 2017
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware23 sep 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
GitHub PoC112
POC Exploit for Apache Tomcat 7.0.x CVE-2017-12615 PUT JSP vulnerability.
CVE-2017-12615HIGHbajo ataqueransomware23 sep 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9791CRITICALbajo ataque23 sep 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
GitHub PoC
Metasploit module for Apache Struts CVE-2017-9791 Remote Code Execution Vulnerability
CVE-2017-9791CRITICALbajo ataque23 sep 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
GitHub PoC40
CVE-2017-0785 BlueBorne PoC
CVE-2017-078522 sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
Exploit-DB
Cash Back Comparison Script 1.0 - SQL Injection
CVE-2017-14703webappsphp22 sep 2017
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
GitHub PoC
CVE-2017-0785: BlueBorne PoC
CVE-2017-078522 sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
Exploit-DB
Claydip Airbnb Clone 1.0 - Arbitrary File Upload
CVE-2017-14704webappsphp22 sep 2017
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Larav
23RIESGO
abrir
anteriorpágina 951 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.