Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
Exploit-DBVexDay Proof
Linux Kernel < 4.10.13 - 'keyctl_set_reqkey_keyring' Local Denial of Service
CVE-2017-7472doslinux07 jun 2017
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumptio
23RIESGO
abrir
Exploit-DBVexDay Proof
PuTTY < 0.68 - 'ssh_agent_channel_data' Integer Overflow Heap Corruption
CVE-2017-6542doslinux07 jun 2017
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large
28RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel - 'ping' Local Denial of Service
CVE-2017-2671dosandroid07 jun 2017
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock a
23RIESGO
abrir
Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
CVE-2017-8837webappscgi06 jun 2017
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-
23RIESGO
abrir
Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
CVE-2017-8835webappscgi06 jun 2017
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw
50RIESGO
abrir
GitHub PoC83
Motorola Untethered Jailbreak: Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass
CVE-2016-1027706 jun 2017
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RIESGO
abrir
Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
CVE-2017-8836webappscgi06 jun 2017
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_
23RIESGO
abrir
Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
CVE-2017-8841webappscgi06 jun 2017
Arbitrary file deletion exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b30
23RIESGO
abrir
Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
CVE-2017-8840webappscgi06 jun 2017
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before f
23RIESGO
abrir
Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
CVE-2017-8839webappscgi06 jun 2017
XSS via orig_url exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_38
23RIESGO
abrir
Exploit-DB
Apple Safari 10.1 - Spread Operator Integer Overflow Remote Code Execution
CVE-2017-2536remotemacos06 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
28RIESGO
abrir
Exploit-DB
Apache Struts - REST Plugin With Dynamic Method Invocation Remote Code Execution
CVE-2016-3087remotemultiple06 jun 2017
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RIESGO
abrir
Exploit-DB
Peplink Balance Routers 7.0.0-build1904 - SQL Injection / Cross-Site Scripting / Information Disclosure
CVE-2017-8838webappscgi06 jun 2017
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380h
23RIESGO
abrir
Exploit-DBVexDay Proof
DNSTracer 1.8.1 - Buffer Overflow (PoC)
CVE-2017-9430doslinux05 jun 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
Exploit-DB
Subsonic 6.1.1 - Server-Side Request Forgery
CVE-2017-9413webappswindows05 jun 2017
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attacke
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALbajo ataqueransomware05 jun 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 2.2.6 - IPv6 Dissector Denial of Service
CVE-2017-9353dosmultiple05 jun 2017
In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by vali
28RIESGO
abrir
Exploit-DBVexDay Proof
Subsonic 6.1.1 - XML External Entity Injection
CVE-2017-9355localwindows05 jun 2017
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to
28RIESGO
abrir
Exploit-DBVexDay Proof
Subsonic 6.1.1 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2017-9414webappswindows05 jun 2017
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote atta
28RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 2.2.0 < 2.2.12 - ROS Dissector Denial of Service
CVE-2017-9347dosmultiple05 jun 2017
In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/d
28RIESGO
abrir
Exploit-DB
BIND 9.10.5 - Unquoted Service Path Privilege Escalation
CVE-2017-3141HIGHlocalwindows05 jun 2017
Windows service and uninstall paths are not quoted when BIND is installed
41RIESGO
abrir
Exploit-DB
Subsonic 6.1.1 - Cross-Site Request Forgery
CVE-2017-9415webappswindows05 jun 2017
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target u
23RIESGO
abrir
GitHub PoC259
Remote root exploit for the SAMBA CVE-2017-7494 vulnerability
CVE-2017-7494CRITICALbajo ataqueransomware05 jun 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DB
WordPress Plugin Event List < 0.7.8 - SQL Injection
CVE-2017-9429webappsphp04 jun 2017
SQL injection vulnerability in the Event List plugin 0.7.8 for WordPress allows an authenticated user to execute arbitra
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-100036704 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
GitHub PoC1
homjxi0e/CVE-2017-1000367
CVE-2017-100036704 jun 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
Exploit-DB
WordPress Plugin WP-Testimonials < 3.4.1 - SQL Injection
CVE-2017-9418webappsphp03 jun 2017
SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute ar
23RIESGO
abrir
GitHub PoC56
Exploiting CVE-2016-4657 to JailBreak the Nintendo Switch
CVE-2016-4657HIGHbajo ataque02 jun 2017
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir
Exploit-DB
Sungard eTRAKiT3 <= 3.2.1.17 - SQL Injection
CVE-2016-6566webappsjson02 jun 2017
The Sungard eTRAKiT3 software version 3.2.1.17 may be vulnerable to SQL injection which may allow a remote unauthenticated attacker to run a subset of SQL commands against the back-end database
28RIESGO
abrir
Exploit-DB
HPE Intelligent Management Center (iMC) 7.2 (E0403P10) - Code Execution
CVE-2017-5815remotelinux02 jun 2017
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
35RIESGO
abrir
anteriorpágina 969 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.