Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
Exploit-DB
Firefox 50.0.1 - ASM.JS JIT-Spray Remote Code Execution
CVE-2017-5375remotewindows14 jul 2017
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
35RIESGO
abrir
Metasploit400
OrientDB 2.2.x Remote Code Execution
CVE-2017-1146713 jul 2017
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which a
60RIESGO
abrir
Metasploit600
Evince CBT File Command Injection
CVE-2017-100008313 jul 2017
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir
Exploit-DB
OrientDB - Code Execution
CVE-2017-11467remotewindows13 jul 2017
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which a
60RIESGO
abrir
Exploit-DB
Skype for Business 2016 - Cross-Site Scripting
CVE-2017-8550remotewindows12 jul 2017
A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted
28RIESGO
abrir
Exploit-DB
360 Total Security - Local Privilege Escalation
CVE-2017-12653remotewindows12 jul 2017
360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any di
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2001-079712 jul 2017
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RIESGO
abrir
VulnCheck XDB
local
CVE-2019-3010HIGHbajo ataque12 jul 2017
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir
VulnCheck XDB
local
CVE-2019-10149CRITICALbajo ataque12 jul 2017
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-7247CRITICALbajo ataque12 jul 2017
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-1466512 jul 2017
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Exploit-DBVexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection
CVE-2017-7175webappslinux11 jul 2017
NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt pa
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)
CVE-2017-0144HIGHbajo ataqueransomwareremotewindows11 jul 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection
CVE-2017-6972webappslinux11 jul 2017
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execu
28RIESGO
abrir
Exploit-DB
DataTaker DT80 dEX 1.50.012 - Information Disclosure
CVE-2017-11165webappshardware11 jul 2017
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a d
50RIESGO
abrir
Exploit-DBVexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM < 5.3.6 - Local Privilege Escalation
CVE-2017-6970locallinux10 jul 2017
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privil
23RIESGO
abrir
Exploit-DBVexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM 5.3.4 - Command Injection
CVE-2017-6971webappslinux10 jul 2017
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts 2.3.x Showcase - Remote Code Execution
CVE-2017-9791CRITICALbajo ataquewebappsmultiple07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
GitHub PoC2
Apache struts struts 2 048, CVE-2017-9791.
CVE-2017-9791CRITICALbajo ataque07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
Exploit-DB
Yaws 1.91 - Remote File Disclosure
CVE-2017-10974remotemultiple07 jul 2017
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: th
60RIESGO
abrir
Metasploit600
Apache Struts 2 Struts 1 Plugin Showcase OGNL Code Execution
CVE-2017-9791CRITICALbajo ataque07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
GitHub PoC24
CVE-2014-1303 (WebKit Heap based BOF) proof of concept for Linux
CVE-2014-130307 jul 2017
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary code and bypass a sandbox
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9791CRITICALbajo ataque07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9791CRITICALbajo ataque07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
GitHub PoC27
CVE-2017-9791
CVE-2017-9791CRITICALbajo ataque07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
Exploit-DBVexDay Proof
LibTIFF - 'tif_jbig.c' Denial of Service
CVE-2017-9936doslinux06 jul 2017
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a
23RIESGO
abrir
Exploit-DBVexDay Proof
LibTIFF - '_TIFFVGetField (tiffsplit)' Out-of-Bounds Read
CVE-2017-9147doslinux06 jul 2017
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cau
23RIESGO
abrir
Exploit-DBVexDay Proof
LibTIFF - 'tif_dirwrite.c' Denial of Service
CVE-2017-10688doslinux06 jul 2017
In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A
23RIESGO
abrir
Exploit-DBVexDay Proof
GoAutoDial CE 3.3 - Authentication Bypass / Command Injection (Metasploit)
CVE-2015-2845remoteunix05 jul 2017
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arb
60RIESGO
abrir
Exploit-DBVexDay Proof
GoAutoDial CE 3.3 - Authentication Bypass / Command Injection (Metasploit)
CVE-2015-2843remoteunix05 jul 2017
Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute
50RIESGO
abrir
anteriorpágina 963 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.