Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.183exploits catalogados
37.028CVEs con explotación pública
24.695probados en laboratorio
80.183 exploits
Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
CVE-2017-12965webappsphp21 ago 2017
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa
28RIESGO
abrir
Exploit-DB
Apache2Triad 1.5.4 - Multiple Vulnerabilities
CVE-2017-12971webappsphp21 ago 2017
Cross-site scripting (XSS) vulnerability in Apache2Triad 1.5.4 allows remote attackers to inject arbitrary web script or
23RIESGO
abrir
Exploit-DB
Apple macOS Sierra 10.12.1 - 'IOFireWireFamily' FireWire Port Denial of Service
CVE-2016-7608dosmacos19 ago 2017
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireF
23RIESGO
abrir
Exploit-DB
WebKitGTK 2.1.2 (Ubuntu 14.04) - Heap based Buffer Overflow
CVE-2014-1303locallinux19 ago 2017
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RIESGO
abrir
GitHub PoC2
CVE-2016-7608: Buffer overflow in IOFireWireFamily.
CVE-2016-760819 ago 2017
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireF
23RIESGO
abrir
Exploit-DB
ZKTime Web Software 2.0 - Cross-Site Request Forgery
CVE-2017-13129webappswindows18 ago 2017
Cross-site request forgery (CSRF) vulnerability in ZKTeco ZKTime Web 2.0.1.12280 allows remote authenticated users to hi
23RIESGO
abrir
Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
CVE-2017-12786doshardware18 ago 2017
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW40
28RIESGO
abrir
GitHub PoC2
GitのCommand Injectionの脆弱性を利用してスクリプトを落として実行する例
CVE-2017-100011718 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Messaging Gateway 10.6.3-2 - Root Remote Command Execution
CVE-2017-6327HIGHbajo ataquewebappsjsp18 ago 2017
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situ
83RIESGO
abrir
Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
CVE-2017-12787doshardware18 ago 2017
A network interface of the novi_process_manager_daemon service, included in the NoviWare software distribution through N
28RIESGO
abrir
Exploit-DB
NoviFlow NoviWare < NW400.2.6 - Multiple Vulnerabilities
CVE-2017-12785doshardware18 ago 2017
The novish command-line interface, included in the NoviWare software distribution through NW400.2.6 and deployed on Novi
28RIESGO
abrir
Exploit-DB
ZKTime Web Software 2.0 - Improper Access Restrictions
CVE-2017-14680webappswindows18 ago 2017
ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a P
23RIESGO
abrir
GitHub PoC2
An EXP could run on Windows x64 against CVE-2008-4654.
CVE-2008-465418 ago 2017
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir
Exploit-DB
QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities
CVE-2017-9979webappsxml18 ago 2017
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be t
23RIESGO
abrir
Exploit-DB
Mozilla Firefox < 45.0 - 'nsHtml5TreeBuilder' Use-After-Free (EMET 5.52 Bypass)
CVE-2016-1960remotewindows18 ago 2017
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox
35RIESGO
abrir
Exploit-DB
QuantaStor Software Defined Storage < 4.3.1 - Multiple Vulnerabilities
CVE-2017-9978webappsxml18 ago 2017
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 40.15063.0.0 Chakra - Incorrect JIT Optimization with TypedArray Setter #3
CVE-2017-8601doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to execute
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptFunction::EntryCall' Fails to Handle 'CallInfo' Properly
CVE-2017-8671doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'TryUndeleteProperty' Incorrect Usage (Denial of Service)
CVE-2017-8635doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
35RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra - Heap Buffer Overflow
CVE-2017-8636doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'EmitNew' Integer Overflow
CVE-2017-8636doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra - Buffer Overflow
CVE-2017-8636doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Invoke Accesses Trait Out-of-Bounds
CVE-2017-3106doswindows17 ago 2017
Adobe Flash Player versions 26.0.0.137 and earlier have an exploitable type confusion vulnerability when parsing SWF fil
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InterpreterStackFrame::ProcessLinkFailedAsmJsModule' Incorrectly Re-parses
CVE-2017-8645doswindows17 ago 2017
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra - 'chakra!Js::GlobalObject' Integer overflow
CVE-2017-8641doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra - NULL Pointer Dereference
CVE-2017-8636doswindows17 ago 2017
Microsoft browsers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Serve
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'PreVisitCatch' Missing Call
CVE-2017-8656doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InterpreterStackFrame::ProcessLinkFailedAsmJsModule' Incorrect Usage of 'PushPopFrameHelper' (Denial of Service)
CVE-2017-8646doswindows17 ago 2017
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Out-of-Bounds Access when Fetching Source
CVE-2017-8657doswindows17 ago 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
35RIESGO
abrir
GitHub PoC
ikmski/CVE-2017-1000117
CVE-2017-100011717 ago 2017
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
anteriorpágina 957 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.