Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
Exploit-DB
WordPress Plugin WP Jobs < 1.5 - SQL Injection
CVE-2017-9603webappsphp11 jun 2017
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
VMware vSphere Data Protection 5.x/6.x - Java Deserialization
CVE-2017-4914remotemultiple10 jun 2017
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of th
23RIESGO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-9127doslinux09 jun 2017
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a deni
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS - Disk Arbitration Daemon Race Condition
CVE-2017-2533localmacos09 jun 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitra
23RIESGO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-9125doslinux09 jun 2017
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of se
23RIESGO
abrir
Metasploit600
IPFire proxy.cgi RCE
CVE-2017-975709 jun 2017
IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a
30RIESGO
abrir
Exploit-DB
libcroco 0.6.12 - Denial of Service
CVE-2017-8871doslinux09 jun 2017
The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial o
28RIESGO
abrir
Exploit-DB
nuevoMailer 6.0 - SQL Injection
CVE-2017-9730webappsphp09 jun 2017
SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-9128doslinux09 jun 2017
The quicktime_video_width function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of
23RIESGO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-9124doslinux09 jun 2017
The quicktime_match_32 function in util.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (NU
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.3 / iOS < 10.3.2 - Userspace Entitlement Checking Race Condition
CVE-2017-7004localmultiple09 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The
23RIESGO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-9122doslinux09 jun 2017
The quicktime_read_moov function in moov.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (i
23RIESGO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-9123doslinux09 jun 2017
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of se
23RIESGO
abrir
Exploit-DB
libquicktime 1.2.4 - Denial of Service
CVE-2017-9126doslinux09 jun 2017
The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of serv
23RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-2671
CVE-2017-267108 jun 2017
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock a
23RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2017-100036708 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
GitHub PoC1
Struts-RCE CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware08 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware08 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities
CVE-2017-11470webappswindows08 jun 2017
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the
23RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-7472
CVE-2017-747208 jun 2017
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumptio
23RIESGO
abrir
GitHub PoC6
own implementation of the CVE-2017-1000367 sudo privilege escalation vulnerability in python
CVE-2017-100036708 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware08 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities
CVE-2017-11471webappswindows08 jun 2017
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatIfGadget/getmetrics.php via the el
23RIESGO
abrir
Exploit-DB
Net Monitor for Employees Pro < 5.3.4 - Unquoted Service Path Privilege Escalation
CVE-2017-7180localwindows08 jun 2017
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its
23RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-9430
CVE-2017-943008 jun 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
Exploit-DB
Craft CMS 2.6 - Cross-Site Scripting
CVE-2017-9516webappsphp08 jun 2017
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
23RIESGO
abrir
Exploit-DBVexDay Proof
VMware Workstation 12 Pro - Denial of Service
CVE-2017-4916doswindows08 jun 2017
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Succes
23RIESGO
abrir
Exploit-DB
IDERA Uptime Monitor 7.8 - Multiple Vulnerabilities
CVE-2017-11469webappswindows08 jun 2017
get2post.php in IDERA Uptime Monitor 7.8 has directory traversal in the file_name parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Artifex MuPDF - Null Pointer Dereference
CVE-2017-5991doslinux07 jun 2017
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function i
28RIESGO
abrir
GitHub PoC
smancke/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware07 jun 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
anteriorpágina 968 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.