Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DB
ERS Data System 1.8.1 - Java Deserialization
CVE-2017-14702remotewindows21 sep 2017
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.Upd
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'Parser::ParseCatch' Does Not Handle 'eval()' (Denial of Service)
CVE-2017-11764doswindows21 sep 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptFunction::ReparseAsmJsModule' Incorrectly Re-parses
CVE-2017-8755doswindows21 sep 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes
CVE-2017-8740doswindows21 sep 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RIESGO
abrir
Exploit-DB
PHPMyFAQ 2.9.8 - Cross-Site Scripting (1)
CVE-2017-14618webappsphp21 sep 2017
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Chakra Incorrectly Parses Object Patterns
CVE-2017-8729doswindows21 sep 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RIESGO
abrir
Exploit-DB
Linux Kernel < 4.13.1 - BlueTooth Buffer Overflow (PoC)
CVE-2017-1000251doslinux21 sep 2017
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and includ
28RIESGO
abrir
Exploit-DB
Apache Tomcat < 9.0.1 (Beta) / < 8.5.23 / < 8.0.47 / < 7.0.8 - JSP Upload Bypass / Remote Code Execution (1)
CVE-2017-12615HIGHbajo ataqueransomwarewebappswindows20 sep 2017
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
Exploit-DB
Android Bluetooth - 'Blueborne' Information Leak (2)
CVE-2017-0785remoteandroid20 sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC463
Blueborne CVE-2017-0785 Android information leak vulnerability
CVE-2017-078520 sep 2017
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
GitHub PoC2
CVE-2017-9798
CVE-2017-979820 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - Memory Corruption with Partial Page Loading
CVE-2017-8731doswindows19 sep 2017
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the
35RIESGO
abrir
Metasploit600
DenyAll Web Application Firewall Remote Code Execution
CVE-2017-1470619 sep 2017
DenyAll WAF before 6.4.1 allows unauthenticated remote attackers to obtain authentication information by making a typeOf
23RIESGO
abrir
GitHub PoC
viethdgit/CVE-2017-0199
CVE-2017-0199HIGHbajo ataqueransomware19 sep 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
Exploit-DB
HPE < 7.2 - Java Deserialization
CVE-2016-4372remotejava19 sep 2017
HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01,
28RIESGO
abrir
GitHub PoC
CVE-2017-8759
CVE-2017-8759HIGHbajo ataque19 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8759HIGHbajo ataque19 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - 'COptionsCollectionCacheItem::GetAt' Out-of-Bounds Read
CVE-2017-8734doswindows19 sep 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arb
35RIESGO
abrir
GitHub PoC2
Two versions of CVE-2017-8759 exploits
CVE-2017-8759HIGHbajo ataque19 sep 2017
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-979818 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'nt!NtSetIoCompletion / nt!NtRemoveIoCompletion' Pool Memory Disclosure
CVE-2017-8708doswindows18 sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
GitHub PoC3
Checks a shared hosting environment for CVE-2017-9798
CVE-2017-979818 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
Exploit-DB
Apache < 2.2.34 / < 2.4.27 - OPTIONS Memory Leak
CVE-2017-9798webappslinux18 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtQueryCompositionSurfaceBinding' Stack Memory Disclosure
CVE-2017-8678doswindows18 sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiDoBanding' Stack Memory Disclosure
CVE-2017-8687doswindows18 sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetGlyphOutline' Pool Memory Disclosure
CVE-2017-8680doswindows18 sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' '.TTF' Font Processing Out-of-Bounds Reads/Writes with Malformed 'fpgm' table 'win32k!bGeneratePath' (Denial of Service)
CVE-2017-8682doswindows18 sep 2017
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a
35RIESGO
abrir
Metasploit300
Apache Optionsbleed Scanner
CVE-2017-979818 sep 2017
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' '.TTF' Font Processing Out-of-Bounds Read with Malformed 'glyf' Table 'win32k!fsc_CalcGrayRow' (Denial of Service)
CVE-2017-8683doswindows18 sep 2017
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetFontResourceInfoInternalW' Stack Memory Disclosure
CVE-2017-8684doswindows18 sep 2017
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R
23RIESGO
abrir
anteriorpágina 952 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.