Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
Exploit-DBVexDay Proof
Fortinet FortiOS < 5.6.0 - Cross-Site Scripting
CVE-2017-3132webappshardware28 jul 2017
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthor
38RIESGO
abrir
GitHub PoC1
搭建漏洞利用测试环境
CVE-2017-7494CRITICALbajo ataqueransomware28 jul 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
CVE-2017-9260doslinux28 jul 2017
The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attack
23RIESGO
abrir
Exploit-DB
LAME 3.99.5 - Multiple Vulnerabilities
CVE-2017-9411doslinux28 jul 2017
20RIESGO
abrir
Exploit-DB
LAME 3.99.5 - Multiple Vulnerabilities
CVE-2017-9410doslinux28 jul 2017
20RIESGO
abrir
Exploit-DB
LAME 3.99.5 - Multiple Vulnerabilities
CVE-2017-9412doslinux28 jul 2017
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of ser
23RIESGO
abrir
Exploit-DB
SoundTouch 1.9.2 - Multiple Vulnerabilities
CVE-2017-9258doslinux28 jul 2017
The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to
23RIESGO
abrir
Exploit-DB
libjpeg-turbo 1.5.1 - Denial of Service
CVE-2017-9614doslinux28 jul 2017
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service
23RIESGO
abrir
GitHub PoC55
CVE-2017-5689 Proof-of-Concept exploit
CVE-2017-5689CRITICALbajo ataque27 jul 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU libiberty - Buffer Overflow
CVE-2016-2226doslinux27 jul 2017
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-5689CRITICALbajo ataque27 jul 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir
Exploit-DBVexDay Proof
AudioCoder 0.8.46 - Local Buffer Overflow (SEH)
CVE-2017-8870localwindows26 jul 2017
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir
Exploit-DB
Microsoft Windows - '.LNK' Shortcut File Code Execution (Metasploit)
CVE-2017-8464HIGHbajo ataquelocalwindows26 jul 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'JSArray::appendMemcpy' Uninitialized Memory Copy
CVE-2017-7064dosmultiple25 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'ArgumentsEliminationPhase::transform' Incorrect LoadVarargs Handling
CVE-2017-7056dosmultiple25 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'JSObject::putInlineSlow' / 'JSValue::putToPrimitive' Universal Cross-Site Scripting
CVE-2017-7037webappsmultiple25 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'DFG::ByteCodeParser::flush(InlineStackEntry* inlineStackEntry)' Incorrect Scope Register Handling
CVE-2017-7018dosmultiple25 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
GitHub PoC3
Exploit created by: R4v3nBl4ck end Pacman
CVE-2017-5638CRITICALbajo ataqueransomware24 jul 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
ManageEngine Desktop Central 10 Build 100087 - Remote Code Execution (Metasploit)
CVE-2017-11346webappsjava24 jul 2017
Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors invo
35RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-5638CRITICALbajo ataqueransomware24 jul 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
Nitro Pro PDF - Multiple Vulnerabilities
CVE-2017-7950localwindows24 jul 2017
Nitro Pro 11.0.3 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted PCX
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8570HIGHbajo ataque24 jul 2017
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer - 'mshtml.dll' Remote Code Execution (MS17-007)
CVE-2017-0037HIGHbajo ataqueremotewindows_x86-6424 jul 2017
Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilde
93RIESGO
abrir
Exploit-DB
Linux Kernel - 'BadIRET' Local Privilege Escalation
CVE-2014-9322locallinux24 jul 2017
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RIESGO
abrir
Metasploit600
Nitro Pro PDF Reader 11.0.3.173 Javascript API Remote Code Execution
CVE-2017-744224 jul 2017
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory tra
50RIESGO
abrir
GitHub PoC66
ppsx file generator for cve-2017-8570 (based on bhdresh/cve-2017-8570)
CVE-2017-8570HIGHbajo ataque24 jul 2017
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
Exploit-DB
vBulletin 5.1.2 < 5.1.9 - Unserialize Code Execution (Metasploit)
CVE-2015-7808webappsphp24 jul 2017
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::Node::getFlag' Use-After-Free
CVE-2017-7041dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderSearchField::addSearchResult' Heap Buffer Overflow
CVE-2017-7049dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderObject' with Accessibility Enabled Use-After-Free
CVE-2017-7046dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
anteriorpágina 961 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.