Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
Exploit-DB
Mantis Bug Tracker 1.3.10/2.3.0 - Cross-Site Request Forgery
CVE-2017-7620webappsphp20 may 2017
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequen
23RIESGO
abrir
Exploit-DB
Secure Auditor 3.0 - Directory Traversal
CVE-2017-9024remotewindows20 may 2017
Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Tra
28RIESGO
abrir
Exploit-DB
Tecnovision DLX Spot - SSH Backdoor Access
CVE-2017-12929remotemultiple19 may 2017
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users
28RIESGO
abrir
Exploit-DB
Oracle PeopleSoft - Server-Side Request Forgery
CVE-2017-3546webappsjava19 may 2017
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChann
23RIESGO
abrir
Exploit-DB
Tecnovision DLX Spot - Authentication Bypass
CVE-2017-12930webappsphp19 may 2017
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users
23RIESGO
abrir
GitHub PoC
WordPress 4.6 - Remote Code Execution (RCE) PoC Exploit
CVE-2016-10033CRITICALbajo ataque19 may 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC
Install patch for CVE-2017-0145 AKA WannaCry.
CVE-2017-0145HIGHbajo ataqueransomware19 may 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DB
Tecnovision DLX Spot - SSH Backdoor Access
CVE-2017-12930remotemultiple19 may 2017
SQL Injection in the admin interface in TecnoVISION DLX Spot Player4 version >1.5.10 allows remote unauthenticated users
23RIESGO
abrir
Exploit-DB
Tecnovision DLX Spot - Arbitrary File Upload
CVE-2017-12929webappsphp19 may 2017
Arbitrary File Upload in resource.php of TecnoVISION DLX Spot Player4 version >1.5.10 allows remote authenticated users
28RIESGO
abrir
Exploit-DB
SAP Business One for Android 1.2.3 - XML External Entity Injection
CVE-2016-6256webappsxml19 may 2017
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RIESGO
abrir
Exploit-DB
Joomla! 3.7.0 - 'com_fields' SQL Injection
CVE-2017-8917webappsphp19 may 2017
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
GitHub PoC7
Joomla 3.7 SQL injection (CVE-2017-8917)
CVE-2017-891719 may 2017
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
Exploit-DB
KDE 4/5 - 'KAuth' Local Privilege Escalation
CVE-2017-8422locallinux18 may 2017
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and le
23RIESGO
abrir
Exploit-DB
KDE 4/5 - 'KAuth' Local Privilege Escalation
CVE-2017-8849locallinux18 may 2017
smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount hel
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8/8.1/2012 R2 (x64) - 'EternalBlue' SMB Remote Code Execution (MS17-010)
CVE-2017-0144HIGHbajo ataqueransomwareremotewindows_x86-6417 may 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DB
INFOR EAM 11.0 Build 201410 - 'filtervalue' SQL Injection
CVE-2017-7952webappsxml17 may 2017
INFOR EAM V11.0 Build 201410 has SQL injection via search fields, related to the filtervalue parameter.
23RIESGO
abrir
Exploit-DB
INFOR EAM 11.0 Build 201410 - Persistent Cross-Site Scripting via Comment Fields
CVE-2017-7953webappsxml17 may 2017
INFOR EAM V11.0 Build 201410 has XSS via comment fields.
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Running Object Table Register ROTFLAGS_ALLOWANYCLIENT Privilege Escalation
CVE-2017-0214doswindows17 may 2017
Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7/2008 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)
CVE-2017-0144HIGHbajo ataqueransomwareremotewindows17 may 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DB
Oracle PeopleSoft Enterprise PeopleTools < 8.55 - Remote Code Execution Via Blind XML External Entity
CVE-2017-3548webappsjava17 may 2017
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integratio
35RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS < 10.3.2 - Notifications API Denial of Service
CVE-2017-6982dosios17 may 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. The issue involves the "Notifications"
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - COM Aggregate Marshaler/IRemUnknown2 Type Confusion Privilege Escalation
CVE-2017-0213HIGHbajo ataqueransomwarelocalwindows17 may 2017
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Read in Getting TextField Width
CVE-2017-3064dosmultiple17 may 2017
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a sh
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Margin Handling Heap Corruption
CVE-2017-3061dosmultiple17 may 2017
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser
28RIESGO
abrir
Metasploit600
Joomla Component Fields SQLi Remote Code Execution
CVE-2017-891717 may 2017
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - AVC Deblocking Out-of-Bounds Read
CVE-2017-3068dosmultiple17 may 2017
Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced V
28RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin PHPMailer 4.6 - Host Header Command Injection (Metasploit)
CVE-2016-10033CRITICALbajo ataqueremotephp17 may 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque16 may 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
GitHub PoC
cve-2016-0728 exploit and summary
CVE-2016-072816 may 2017
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC88
CVE-2017-7269 to webshell or shellcode loader
CVE-2017-7269CRITICALbajo ataque16 may 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
anteriorpágina 972 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.