Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
VulnCheck XDB
local
CVE-2015-2546HIGHbajo ataqueransomware25 may 2017
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
76RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3(12602.4.8) - 'WebCore::FrameView::scheduleRelayout' Use-After-Free
CVE-2017-2514dosmultiple25 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir
VulnCheck XDB
local
CVE-2017-7494CRITICALbajo ataqueransomware25 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'ContainerNode::parserInsertBefore' Universal Cross-Site Scripting
CVE-2017-2508webappsmultiple25 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'enqueuePageshowEvent' / 'enqueuePopstateEvent' Universal Cross-Site Scripting
CVE-2017-2510webappsmultiple25 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir
Exploit-DB
Sophos Cyberoam - Cross-site scripting
CVE-2016-9834webappshardware25 may 2017
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Soph
23RIESGO
abrir
GitHub PoC181
Proof-of-Concept exploit for CVE-2017-7494(Samba RCE from a writable share)
CVE-2017-7494CRITICALbajo ataqueransomware25 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC21
k0keoyo/CVE-2015-2546-Exploit
CVE-2015-2546HIGHbajo ataqueransomware25 may 2017
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
76RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox < 53 - 'gfxTextRun' Out-of-Bounds Read
CVE-2017-5447dosmultiple25 may 2017
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitabl
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit / Safari 10.0.3(12602.4.8) - 'Editor::Command::execute' Universal Cross-Site Scripting
CVE-2017-2504webappsmultiple25 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'FrameLoader::clear' Stealing Variables via Page Navigation
CVE-2017-2515webappsmultiple25 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-7494
CVE-2017-7494CRITICALbajo ataqueransomware25 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox < 53 - 'ConvolvePixel' Memory Disclosure
CVE-2017-5465dosmultiple25 may 2017
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for other
28RIESGO
abrir
Exploit-DBVexDay Proof
Samba 3.5.0 - Remote Code Execution
CVE-2017-7494CRITICALbajo ataqueransomwareremotelinux24 may 2017
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - 'TIKeyboardLayout initWithCoder:' NSKeyedArchiver Heap Corruption Due to Rounding Error
CVE-2017-2524dosmultiple23 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - Memory Corruption Due to Bad Bounds Checking in NSCharacterSet Coding for NSKeyedUnarchiver
CVE-2017-2522dosmultiple23 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS - Lack of Bounds Checking in HIServices Custom CFObject Serialization Local Privilege Escalation
CVE-2017-6978dosmacos23 may 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Accessibili
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - NSUnarchiver Heap Corruption Due to Lack of Bounds Checking in [NSBuiltinCharacterSet initWithCoder:]
CVE-2017-2523dosmultiple23 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS Kernel - Use-After-Free Due to Bad Locking in Unix Domain Socket File Descriptor Externalization
CVE-2017-2501dosmultiple23 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - 'CAMediaTimingFunctionBuiltin' NSKeyedArchiver Memory Corruption Due to Lack of Bounds Checking
CVE-2017-2527dosmultiple23 may 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "CoreAnimati
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS - '32-bit syscall exit' Kernel Register Leak
CVE-2017-2509dosmacos22 may 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RIESGO
abrir
Metasploit600
VMware Workstation ALSA Config File Local Privilege Escalation
CVE-2017-491522 may 2017
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration fil
38RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS - 'stackshot' Raw Frame Pointers
CVE-2017-2516dosmacos22 may 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RIESGO
abrir
Exploit-DBVexDay Proof
VMware Workstation for Linux 12.5.2 build-4638234 - ALSA Configuration Host Local Privilege Escalation
CVE-2017-4915locallinux22 may 2017
VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration fil
38RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.11 - eBPF Verifier Log Leaks Lower Half of map Pointer
CVE-2017-9150doslinux22 may 2017
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value
23RIESGO
abrir
Exploit-DBVexDay Proof
PlaySMS 1.4 - 'import.php' Remote Code Execution
CVE-2017-9101webappsphp21 may 2017
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RIESGO
abrir
GitHub PoC3
Admidio 3.2.8 Cross-Site Request Forgery Assigned CVE Number: CVE-2017-8382
CVE-2017-838221 may 2017
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RIESGO
abrir
Metasploit600
PlaySMS import.php Authenticated CSV File Upload Code Execution
CVE-2017-910121 may 2017
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RIESGO
abrir
Metasploit600
PlaySMS sendfromfile.php Authenticated "Filename" Field Code Execution
CVE-2017-908021 may 2017
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile
50RIESGO
abrir
Exploit-DB
Mantis Bug Tracker 1.3.10/2.3.0 - Cross-Site Request Forgery
CVE-2017-7620webappsphp20 may 2017
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequen
23RIESGO
abrir
anteriorpágina 971 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.