Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
Exploit-DB
BOA Web Server 0.94.14rc21 - Arbitrary File Access
CVE-2017-9833webappslinux20 jun 2017
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read
50RIESGO
abrir
Exploit-DB
Freeware Advanced Audio Coder (FAAC) 1.28 - Denial of Service
CVE-2017-9130doslinux20 jun 2017
The faacEncOpen function in libfaac/frame.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to caus
23RIESGO
abrir
Exploit-DB
Freeware Advanced Audio Coder (FAAC) 1.28 - Denial of Service
CVE-2017-9129doslinux20 jun 2017
The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to c
23RIESGO
abrir
Metasploit400
Solaris RSH Stack Clash Privilege Escalation
CVE-2017-362919 jun 2017
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir
Metasploit400
Solaris RSH Stack Clash Privilege Escalation
CVE-2017-363019 jun 2017
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir
Metasploit400
Solaris RSH Stack Clash Privilege Escalation
CVE-2017-363119 jun 2017
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir
Metasploit400
Solaris RSH Stack Clash Privilege Escalation
CVE-2017-100036419 jun 2017
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficie
38RIESGO
abrir
GitHub PoC
InSpec profile to verify a node is patched and compliant for CVE-2017-8543
CVE-2017-8543CRITICALbajo ataque19 jun 2017
Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008
100RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'rx_decode_opcode' Buffer Overflow
CVE-2017-9750doslinux19 jun 2017
opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'bfd_get_string' Stack Buffer Overflow
CVE-2017-9747doslinux19 jun 2017
The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GN
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'disassemble_bytes' Heap Overflow
CVE-2017-9746doslinux19 jun 2017
The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (b
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'print_insn_score16' Buffer Overflow
CVE-2017-9742doslinux19 jun 2017
The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of ser
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'decode_pseudodbg_assert_0' Buffer Overflow
CVE-2017-9749doslinux19 jun 2017
The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'ieee_object_p' Stack Buffer Overflow
CVE-2017-9748doslinux19 jun 2017
The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'aarch64_ext_ldst_reglist' Buffer Overflow
CVE-2017-9756doslinux19 jun 2017
The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a d
23RIESGO
abrir
GitHub PoC2
os experiment 4 CVE-2016-5195
CVE-2016-5195HIGHbajo ataque16 jun 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - arrayProtoFuncSplice does not Initialize all Indices
CVE-2017-6980dosmultiple16 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'Intl.getCanonicalLocales' Heap Buffer Overflow
CVE-2017-6984dosmultiple16 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. iTun
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - JIT Optimization Check Failed in IntegerCheckCombiningPhase::handleBlock
CVE-2017-2547dosmultiple16 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
28RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - JSGlobalObject::haveABadTime Causes Type Confusions
CVE-2017-7005dosmultiple16 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir
Exploit-DB
Sudo 1.8.20 - 'get_process_ttyname()' Local Privilege Escalation
CVE-2017-1000367locallinux14 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
Exploit-DB
KBVault MySQL 0.16a - Arbitrary File Upload
CVE-2017-9602webappsaspx14 jun 2017
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-man
23RIESGO
abrir
Exploit-DB
HP PageWide Printers / HP OfficeJet Pro Printers (OfficeJet Pro 8210) - Arbitrary Code Execution
CVE-2017-2741remotehardware14 jun 2017
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RIESGO
abrir
Exploit-DB
Google Chrome - V8 Private Property Arbitrary Code Execution
CVE-2016-9651remoteandroid14 jun 2017
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a
28RIESGO
abrir
GitHub PoC
CVE-2017-5638 Test environment
CVE-2017-5638CRITICALbajo ataqueransomware13 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Metasploit200
Microsoft Windows RRAS Service MIBEntryGet Overflow
CVE-2017-846113 jun 2017
Windows RPC with Routing and Remote Access enabled in Windows XP and Windows Server 2003 allows an attacker to execute c
23RIESGO
abrir
Metasploit500
LNK Code Execution Vulnerability
CVE-2017-8464HIGHbajo ataque13 jun 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
Metasploit500
LNK Code Execution Vulnerability
CVE-2017-8464HIGHbajo ataque13 jun 2017
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
Metasploit300
Easy File Sharing HTTP Server 7.2 POST Buffer Overflow
CVE-2025-34096CRITICAL12 jun 2017
Easy File Sharing HTTP Server 7.2 Buffer Overflow via POST to /sendemail.ghp
63RIESGO
abrir
Exploit-DBVexDay Proof
GStreamer gst-plugins-bad Plugin - NULL Pointer Dereference
CVE-2016-9813doslinux12 jun 2017
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of ser
23RIESGO
abrir
anteriorpágina 967 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.