Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.096exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.180 exploits
Exploit-DB
Apache Struts 2.5 < 2.5.12 - REST Plugin XStream Remote Code Execution
CVE-2017-9805HIGHbajo ataqueremotelinux06 sep 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC60
CVE 2017-9805
CVE-2017-9805HIGHbajo ataque06 sep 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9805HIGHbajo ataque06 sep 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Out-of-Bounds Write Privilege Escalation
CVE-2017-14075localwindows06 sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RIESGO
abrir
Exploit-DBVexDay Proof
Jungo DriverWizard WinDriver < 12.4.0 - Kernel Pool Overflow / Local Privilege Escalation (1)
CVE-2017-14153localwindows06 sep 2017
This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must
23RIESGO
abrir
Metasploit600
Apache Struts 2 REST Plugin XStream RCE
CVE-2017-9805HIGHbajo ataque05 sep 2017
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
Exploit-DB
FiberHome ADSL AN1020-25 - Improper Access Restrictions
CVE-2017-14147webappshardware05 sep 2017
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to ea
35RIESGO
abrir
Exploit-DB
Wireless Repeater BE126 - Remote Code Execution
CVE-2017-13713webappshardware04 sep 2017
T&W WIFI Repeater BE126 allows remote authenticated users to execute arbitrary code via shell metacharacters in the user
23RIESGO
abrir
GitHub PoC
siling2017/CVE-2017-1000117
CVE-2017-100011704 sep 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
Exploit-DB
CodeMeter 6.50 - Cross-Site Scripting
CVE-2017-13754webappsmultiple04 sep 2017
Cross-site scripting (XSS) vulnerability in the "advanced settings - time server" module in Wibu-Systems CodeMeter befor
23RIESGO
abrir
Exploit-DBVexDay Proof
RubyGems < 2.6.13 - Arbitrary File Overwrite
CVE-2017-0901locallinux04 sep 2017
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potenti
28RIESGO
abrir
Exploit-DB
Mongoose Web Server 6.5 - Cross-Site Request Forgery / Remote Code Execution
CVE-2017-11567remotewindows04 sep 2017
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the
23RIESGO
abrir
Metasploit600
Mako Server v2.5, 2.6 OS Command Injection RCE
CVE-2025-34095CRITICAL03 sep 2017
Mako Server v2.5 and v2.6 OS Command Injection via examples/save.lsp
63RIESGO
abrir
Exploit-DBVexDay Proof
IBM Notes 8.5.x/9.0.x - Denial of Service
CVE-2017-1129dosmultiple02 sep 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RIESGO
abrir
Exploit-DB
Lotus Notes Diagnostic Tool 8.5/9.0 - Local Privilege Escalation
CVE-2015-0179localwindows02 sep 2017
Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users t
23RIESGO
abrir
Exploit-DB
Motorola Bootloader - Kernel Cmdline Injection Secure Boot and Device Locking Bypass
CVE-2016-10277localandroid01 sep 2017
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RIESGO
abrir
Metasploit600
Zivif Camera iptest.cgi Blind Remote Command Execution
CVE-2017-1710501 sep 2017
Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauth
40RIESGO
abrir
Exploit-DB
OpenJPEG - 'mqc.c' Heap Buffer Overflow
CVE-2016-10504doslinux01 sep 2017
Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote
23RIESGO
abrir
Exploit-DB
WordPress Plugin Participants Database < 1.7.5.10 - Cross-Site Scripting
CVE-2017-14126webappsphp01 sep 2017
The Participants Database plugin before 1.7.5.10 for WordPress has XSS.
23RIESGO
abrir
Exploit-DB
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.7 - SQL Injection
CVE-2016-1000125webappsphp31 ago 2017
Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla
23RIESGO
abrir
Exploit-DB
IBM Notes 8.5.x/9.0.x - Denial of Service (Metasploit)
CVE-2017-1129dosmultiple31 ago 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RIESGO
abrir
Exploit-DBVexDay Proof
Git < 2.7.5 - Command Injection (Metasploit)
CVE-2017-1000117remotepython31 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
Exploit-DB
Joomla! Component Huge-IT Portfolio Gallery Plugin 1.0.6 - SQL Injection
CVE-2016-1000124webappsphp31 ago 2017
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
23RIESGO
abrir
Exploit-DB
Joomla! Component Huge-IT Video Gallery 1.0.9 - SQL Injection
CVE-2016-1000123webappsphp31 ago 2017
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Notes 8.5.x/9.0.x - Denial of Service (2)
CVE-2017-1130dosmultiple31 ago 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it woul
43RIESGO
abrir
Metasploit300
IBM Notes Denial Of Service
CVE-2017-113031 ago 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it woul
43RIESGO
abrir
Metasploit300
Open WAN-to-LAN proxy on AT&T routers
CVE-2017-1411731 ago 2017
The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589 and NVG599 devices, when IP Passthrough mode is not used, conf
18RIESGO
abrir
Metasploit300
IBM Notes encodeURI DOS
CVE-2017-112931 ago 2017
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
50RIESGO
abrir
Exploit-DBVexDay Proof
Metasploit Web UI < 4.14.1-20170828 - Cross-Site Request Forgery
CVE-2017-15084webappsruby30 ago 2017
The web UI in Rapid7 Metasploit before 4.14.1-20170828 allows logout CSRF, aka R7-2017-22.
23RIESGO
abrir
Exploit-DB
Oracle Java JDK/JRE < 1.8.0.131 / Apache Xerces 2.11.0 - 'PDF/Docx' Server Side Denial of Service
CVE-2017-10355dosphp30 ago 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supporte
28RIESGO
abrir
anteriorpágina 955 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.