Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
Metasploit600
DIR-850L (Un)authenticated OS Command Exec
CVE-2019-1750809 ago 2017
On D-Link DIR-859 A3-1.06 and DIR-850 A1.13 devices, /etc/services/DEVICE.TIME.php allows command injection via the $SER
23RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Messaging Gateway < 10.6.3-267 - Cross-Site Request Forgery
CVE-2017-6328webappsmultiple09 ago 2017
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of cross site request forgery (also known as one
23RIESGO
abrir
Exploit-DB
NoMachine 5.3.9 - Local Privilege Escalation
CVE-2017-12763localosx09 ago 2017
An unspecified server utility in NoMachine before 5.3.10 on Mac OS X and Linux allows authenticated users to gain privil
23RIESGO
abrir
Exploit-DB
Android Bluetooth - 'Blueborne' Information Leak (1)
CVE-2017-0781remoteandroid09 ago 2017
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11152webappshardware08 ago 2017
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 all
28RIESGO
abrir
Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
CVE-2017-11664doslinux08 ago 2017
The _WM_SetupMidiEvent function in internal_midi.c:2122 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
23RIESGO
abrir
Exploit-DBVexDay Proof
Unitrends UEB 9.1 - 'Unitrends bpserverd' Remote Command Execution
CVE-2017-12477remotelinux08 ago 2017
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RIESGO
abrir
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11153webappshardware08 ago 2017
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allo
28RIESGO
abrir
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11155webappshardware08 ago 2017
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remot
35RIESGO
abrir
Metasploit600
Unitrends UEB http api remote code execution
CVE-2018-632808 ago 2017
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, w
50RIESGO
abrir
Exploit-DB
VMware WorkStation 12.5.5 - Virtual Machine Escape
CVE-2017-4901localwindows08 ago 2017
The drag-and-drop (DnD) function in VMware Workstation 12.x before version 12.5.4 and Fusion 8.x before version 8.5.5 ha
28RIESGO
abrir
Metasploit600
Unitrends UEB bpserverd authentication bypass RCE
CVE-2017-1247708 ago 2017
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RIESGO
abrir
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11151webappshardware08 ago 2017
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers
28RIESGO
abrir
Metasploit600
Unitrends UEB http api remote code execution
CVE-2017-1247808 ago 2017
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir
Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
CVE-2017-11661doslinux08 ago 2017
The _WM_SetupMidiEvent function in internal_midi.c:2318 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
28RIESGO
abrir
Exploit-DBVexDay Proof
Unitrends UEB 9.1 - Privilege Escalation
CVE-2017-12479webappsphp08 ago 2017
It was discovered that an issue in the session logic in Unitrends Backup (UB) before 10.0.0 allowed using the LOGDIR env
28RIESGO
abrir
Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
CVE-2017-11663doslinux08 ago 2017
The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
23RIESGO
abrir
Exploit-DBVexDay Proof
Synology Photo Station 6.7.3-3432 / 6.3-2967 - Remote Code Execution
CVE-2017-11154webappshardware08 ago 2017
Unrestricted file upload vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-296
23RIESGO
abrir
Exploit-DB
WildMIDI 0.4.2 - Multiple Vulnerabilities
CVE-2017-11662doslinux08 ago 2017
The _WM_ParseNewMidi function in f_midi.c in WildMIDI 0.4.2 can cause a denial of service (invalid memory read and appli
23RIESGO
abrir
Exploit-DBVexDay Proof
Unitrends UEB 9.1 - Authentication Bypass / Remote Command Execution
CVE-2017-12478remotelinux08 ago 2017
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8464HIGHbajo ataque07 ago 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
GitHub PoC8
this tool can generate a exp for cve-2017-8486, it is developed by python
CVE-2017-8464HIGHbajo ataque07 ago 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
Exploit-DB
Microsoft Windows - '.LNK' Shortcut File Code Execution
CVE-2017-8464HIGHbajo ataquelocalwindows06 ago 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
Metasploit600
QNAP Transcode Server Command Execution
CVE-2017-1306706 ago 2017
QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.
23RIESGO
abrir
GitHub PoC7
Attempt to steal kernelcredentials from launchd + task_t pointer (Based on: CVE-2017-7047)
CVE-2017-704705 ago 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RIESGO
abrir
GitHub PoC4
CVE-2017-2388: Null-pointer dereference in IOFireWireFamily.
CVE-2017-238804 ago 2017
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "IOFireWireF
23RIESGO
abrir
Exploit-DBVexDay Proof
VirtualBox 5.1.22 - Windows Process DLL Signature Bypass Privilege Escalation
CVE-2017-10204localwindows03 ago 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RIESGO
abrir
Exploit-DBVexDay Proof
VirtualBox 5.1.22 - Windows Process DLL UNC Path Signature Bypass Privilege Escalation
CVE-2017-10129localwindows03 ago 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version
23RIESGO
abrir
Exploit-DB
DNSTracer 1.9 - Local Buffer Overflow
CVE-2017-9430locallinux03 ago 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
Exploit-DB
Horde Groupware 5.2.21 - Unauthorized File Download
CVE-2017-15235webappsphp03 ago 2017
The File Manager (gollem) module 3.0.11 in Horde Groupware 5.2.21 allows remote attackers to bypass Horde authentication
23RIESGO
abrir
anteriorpágina 959 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.