Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
GitHub PoC
cve-2016-0728 exploit and summary
CVE-2016-072816 may 2017
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 Kernel - 'nt!NtTraceControl (EtwpSetProviderTraits)' Pool Memory Disclosure
CVE-2017-0259doswindows15 may 2017
The Windows kernel in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - Pool-Based Out-of-Bounds Reads Due to bind() Implementation Bugs in afd.sys / tcpip.sys
CVE-2017-0220doswindows15 may 2017
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows Server 2012 Gold allows authenticat
23RIESGO
abrir
Exploit-DBVexDay Proof
Quest Privilege Manager - pmmasterd Buffer Overflow (Metasploit)
CVE-2017-6553remotelinux15 may 2017
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - 'win32k!xxxClientLpkDrawTextEx' Stack Memory Disclosure
CVE-2017-0245doswindows15 may 2017
The kernel-mode drivers in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1 and Windows Server 2012 Gold allow a local
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - Uninitialized Memory in the Default dacl Descriptor of System Processes Token
CVE-2017-0258doswindows15 may 2017
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 Kernel - Pool-Based Out-of-Bounds Reads Due to bind() Implementation Bugs in afd.sys / tcpip.sys
CVE-2017-0175doswindows15 may 2017
The Windows kernel in Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows authenticated attackers to obtain sen
23RIESGO
abrir
Exploit-DB
Mailcow 0.14 - Cross-Site Request Forgery
CVE-2017-8928webappsphp15 may 2017
mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.
23RIESGO
abrir
Metasploit300
LabF nfsAxe 3.7 FTP Client Stack Buffer Overflow
CVE-2017-1804715 may 2017
Buffer Overflow in the FTP client in LabF nfsAxe 3.7 allows remote FTP servers to execute arbitrary code via a long repl
23RIESGO
abrir
Metasploit600
HPE iMC dbman RestartDB Unauthenticated RCE
CVE-2017-581615 may 2017
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Metasploit600
HPE iMC dbman RestoreDBase Unauthenticated RCE
CVE-2017-581715 may 2017
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Metasploit600
Octopus Deploy Authenticated Code Execution
CVE-2018-1885015 may 2017
In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment
23RIESGO
abrir
Exploit-DBVexDay Proof
Larson VizEx Reader 9.7.5 - Local Buffer Overflow (SEH)
CVE-2017-8927doswindows14 may 2017
Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified
23RIESGO
abrir
Exploit-DBVexDay Proof
Halliburton LogView Pro 10.0.1 - Local Buffer Overflow (SEH)
CVE-2017-8926doswindows14 may 2017
Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspeci
23RIESGO
abrir
Exploit-DB
Dive Assistant Template Builder 8.0 - XML External Entity Injection
CVE-2017-8918localwindows12 may 2017
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely
23RIESGO
abrir
GitHub PoC1
Honeypot for Intel's AMT Firmware Vulnerability CVE-2017-5689
CVE-2017-5689CRITICALbajo ataque12 may 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir
Exploit-DB
Vanilla Forums < 2.3 - Remote Code Execution
CVE-2016-10033CRITICALbajo ataqueremotephp11 may 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-20149CRITICAL11 may 2017
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chi
48RIESGO
abrir
GitHub PoC1
Cisco Catalyst Remote Code Execution PoC
CVE-2017-3881CRITICALbajo ataque11 may 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.8.0-41-generic (Ubuntu) - Packet Socket Local Privilege Escalation
CVE-2017-7308locallinux11 may 2017
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft IIS - WebDav 'ScStoragePathFromUrl' Remote Overflow (Metasploit)
CVE-2017-7269CRITICALbajo ataqueremotewindows11 may 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-0290-
CVE-2017-029011 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
45RIESGO
abrir
Exploit-DB
MiniUPnP MiniUPnPc < 2.0 - Remote Denial of Service
CVE-2017-8798dosmultiple11 may 2017
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of s
28RIESGO
abrir
Exploit-DB
Vanilla Forums < 2.3 - Remote Code Execution
CVE-2016-10073remotephp11 may 2017
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RIESGO
abrir
Exploit-DBVexDay Proof
OpenVPN 2.4.0 - Denial of Service
CVE-2017-7478dosmultiple11 may 2017
OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-3881CRITICALbajo ataque11 may 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
GitHub PoC9
RCE against WordPress 4.6; Python port of https://exploitbox.io/vuln/WordPress-Exploit-4-6-RCE-CODE-EXEC-CVE-2016-10033.html
CVE-2016-10033CRITICALbajo ataque10 may 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0145HIGHbajo ataqueransomwareremotewindows_x86-6410 may 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0146HIGHbajo ataqueransomwareremotewindows_x86-6410 may 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2008 R2 (x64) - 'SrvOs2FeaToNt' SMB Remote Code Execution (MS17-010)
CVE-2017-0143HIGHbajo ataqueransomwareremotewindows_x86-6410 may 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
anteriorpágina 973 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.