Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
GitHub PoC2
POC for java RMI deserialization vulnerability
CVE-2017-324104 jul 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RIESGO
abrir
Exploit-DB
WordPress Plugin WatuPRO 5.5.1 - SQL Injection
CVE-2017-9834webappsphp03 jul 2017
SQL injection vulnerability in the WatuPRO plugin before 5.5.3.7 for WordPress allows remote attackers to execute arbitr
23RIESGO
abrir
GitHub PoC
VideoLAN VLC media player 0.9.4 Media Player ty.c buffer overflow
CVE-2008-465402 jul 2017
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RIESGO
abrir
Exploit-DB
Zookeeper 3.5.2 Client - Denial of Service
CVE-2017-5637dosmultiple02 jul 2017
Two four letter word commands "wchp/wchc" are CPU intensive and could cause spike of CPU utilization on Apache ZooKeeper
45RIESGO
abrir
GitHub PoC57
CVE-2017-0213 for command line
CVE-2017-0213HIGHbajo ataqueransomware01 jul 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2012-268801 jul 2017
Unspecified vulnerability in the _php_stream_scandir function in the stream implementation in PHP before 5.3.15 and 5.4.
28RIESGO
abrir
VulnCheck XDB
local
CVE-2017-0213HIGHbajo ataqueransomware01 jul 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
GitHub PoC
sUbc0ol/Microsoft-Word-CVE-2017-0199-
CVE-2017-0199HIGHbajo ataqueransomware30 jun 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
GitHub PoC
sUbc0ol/Apache-Struts-CVE-2017-5638-RCE-Mass-Scanner
CVE-2017-5638CRITICALbajo ataqueransomware30 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC13
sUbc0ol/Apache-Struts2-RCE-Exploit-v2-CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware30 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-0199HIGHbajo ataqueransomware30 jun 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
Exploit-DB
Odoo CRM 10.0 - Code Execution
CVE-2017-10803locallinux30 jun 2017
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymi
23RIESGO
abrir
GitHub PoC
FreeSSHD Remote Authentication Bypass Vulnerability (freeSSHd 2.1.3)
CVE-2012-606630 jun 2017
freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demons
50RIESGO
abrir
GitHub PoC
sUbc0ol/CVE-2015-0235
CVE-2015-023530 jun 2017
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware30 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware30 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALbajo ataque29 jun 2017
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Exploit-DBVexDay Proof
ActiveMQ < 5.14.0 - Web Shell Upload (Metasploit)
CVE-2016-3088CRITICALbajo ataqueremotejava29 jun 2017
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
GitHub PoC1
CVE-2015-1635
CVE-2015-1635CRITICALbajo ataque29 jun 2017
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Exploit-DBVexDay Proof
Veritas/Symantec Backup Exec - SSL NDMP Connection Use-After-Free (Metasploit)
CVE-2017-8895remotewindows29 jun 2017
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a u
60RIESGO
abrir
GitHub PoC
shaheemirza/CVE-2017-0213-
CVE-2017-0213HIGHbajo ataqueransomware29 jun 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
Exploit-DBVexDay Proof
NetBSD - 'Stack Clash' (PoC)
CVE-2017-1000375dosnetbsd_x8628 jun 2017
NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attacke
28RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - 'setrlimit' Stack Clash (PoC)
CVE-2017-1085dosfreebsd_x8628 jun 2017
In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only mem
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Debian 7.7/8.5/9.0 / Ubuntu 14.04.2/16.04.2/17.04 / Fedora 22/25 / CentOS 7.3.1611) - 'ldso_hwcap_64 Stack Clash' Local Privilege Escalation
CVE-2017-1000379locallinux_x86-6428 jun 2017
The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where
23RIESGO
abrir
Exploit-DBVexDay Proof
Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities
CVE-2017-9813webappslinux28 jun 2017
In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the scriptNa
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Solaris 11.1/11.3 (RSH) - 'Stack Clash' Local Privilege Escalation
CVE-2017-3630localsolaris_x8628 jun 2017
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Solaris 11.1/11.3 (RSH) - 'Stack Clash' Local Privilege Escalation
CVE-2017-3631localsolaris_x8628 jun 2017
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir
GitHub PoC
qwertyuiop12138/CVE-2016-10033
CVE-2016-10033CRITICALbajo ataque28 jun 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Solaris 11.1/11.3 (RSH) - 'Stack Clash' Local Privilege Escalation
CVE-2017-3629localsolaris_x8628 jun 2017
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel - 'offset2lib' Stack Clash
CVE-2017-1000370locallinux_x8628 jun 2017
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RIESGO
abrir
anteriorpágina 964 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.