Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
VulnCheck XDB
client-side
CVE-2016-4657HIGHbajo ataque02 jun 2017
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - CachedFrame does not Detach Openers Universal Cross-Site Scripting
CVE-2017-2528webappsmultiple01 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'JSObject::ensureLength' ensureLengthSlow Check Failure
CVE-2017-2521doslinux01 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - Incorrect Check in emitPutDerivedConstructorToArrowFunctionContextScope
CVE-2017-2531dosmultiple01 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir
Metasploit300
Riverbed SteelHead VCX File Read
CVE-2025-34098HIGH01 jun 2017
Riverbed SteelHead VCX Authenticated Arbitrary File Read via Log Filter Injection
36RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Remote Use-After-Free Due to Design Issue in GC Engine
CVE-2017-8540HIGHbajo ataquedoswindows30 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
93RIESGO
abrir
Metasploit600
IBM OpenAdmin Tool SOAP welcomeServer PHP Code Execution
CVE-2017-109230 may 2017
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RIESGO
abrir
GitHub PoC58
It is a simple script to exploit RCE for Samba (CVE-2017-7494 ).
CVE-2017-7494CRITICALbajo ataqueransomware30 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Use-After-Free via Saved Callers
CVE-2017-8541doswindows30 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
35RIESGO
abrir
GitHub PoC119
Exploits for CVE-2017-6008, a kernel pool buffer overflow leading to privilege escalation.
CVE-2017-600830 may 2017
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALbajo ataqueransomware30 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-100036730 may 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Informix Dynamic Server / Informix Open Admin Tool - DLL Injection / Remote Code Execution / Heap Buffer Overflow
CVE-2017-1092webappswindows30 may 2017
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RIESGO
abrir
GitHub PoC114
c0d3z3r0/sudo-CVE-2017-1000367
CVE-2017-100036730 may 2017
Todd Miller's sudo version 1.8.20 and earlier is vulnerable to an input validation (embedded spaces) in the get_process_
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8537doswindows29 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8536doswindows29 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8535doswindows29 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RIESGO
abrir
Exploit-DBVexDay Proof
Samba 3.5.0 < 4.4.14/4.5.10/4.6.4 - 'is_known_pipename()' Arbitrary Module Load (Metasploit)
CVE-2017-7494CRITICALbajo ataqueransomwareremotelinux29 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8538doswindows29 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
35RIESGO
abrir
GitHub PoC1
An exploit (and library) for CVE-2017-5638 - Apache Struts2 S2-045 bug.
CVE-2017-5638CRITICALbajo ataqueransomware28 may 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
An exploit for CVE-2017-5638 Remote Code Execution (RCE) Vulnerability in Apache Struts 2
CVE-2017-5638CRITICALbajo ataqueransomware28 may 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware28 may 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware28 may 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware27 may 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware27 may 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC380
SambaCry exploit and vulnerable container (CVE-2017-7494)
CVE-2017-7494CRITICALbajo ataqueransomware26 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALbajo ataqueransomware26 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Metasploit600
VICIdial user_authorization Unauthenticated Command Execution
CVE-2025-34099CRITICAL26 may 2017
VICIdial vicidial_sales_viewer.php Unauthenticated Command Injection via Basic Auth Password
63RIESGO
abrir
GitHub PoC63
CVE-2017-7494 - Detection Scripts
CVE-2017-7494CRITICALbajo ataqueransomware26 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting
CVE-2017-2510webappsmultiple25 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir
anteriorpágina 970 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.