Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
GitHub PoC39
CerberusSecurity/CVE-2017-5689
CVE-2017-5689CRITICALbajo ataque04 may 2017
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Mana
100RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari 10.0.3 - 'JSC::CachedCall' Use-After-Free
CVE-2017-2491remotemacos04 may 2017
Use after free vulnerability in the String.replace method JavaScriptCore in Apple Safari in iOS before 10.3 allows remot
23RIESGO
abrir
GitHub PoC2
RedDot CMS versions 7.5 Build 7.5.0.48 and below full database enumeration exploit that takes advantage of a remote SQL injection vulnerability in ioRD.asp.
CVE-2008-161303 may 2017
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and
23RIESGO
abrir
Metasploit600
Crypttech CryptoLog Remote Code Execution
CVE-2025-34102CRITICAL03 may 2017
CryptoLog Unauthenticated RCE via SQL Injection and Command Injection
63RIESGO
abrir
Metasploit600
Serviio Media Server checkStreamUrl Command Execution
CVE-2025-34101CRITICAL03 may 2017
Serviio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter
63RIESGO
abrir
Metasploit200
WordPress PHPMailer Host Header Command Injection
CVE-2016-10033CRITICALbajo ataque03 may 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Exploit-DB
WordPress Core 4.6 - Remote Code Execution
CVE-2016-10033CRITICALbajo ataquewebappslinux03 may 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Exploit-DB
WordPress Core < 4.7.4 - Unauthorized Password Reset
CVE-2017-8295webappslinux03 may 2017
WordPress through 4.7.4 relies on the Host HTTP header for a password-reset e-mail message, which makes it easier for re
28RIESGO
abrir
GitHub PoC3
Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection
CVE-2008-541603 may 2017
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2017-3881-Cisco
CVE-2017-3881CRITICALbajo ataque02 may 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-3881CRITICALbajo ataque02 may 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
Exploit-DBVexDay Proof
Ghostscript 9.21 - Type Confusion Arbitrary Command Execution (Metasploit)
CVE-2017-8291HIGHbajo ataquelocallinux02 may 2017
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir
Exploit-DBVexDay Proof
MySQL < 5.6.35 / < 5.7.17 - Integer Overflow
CVE-2017-3599dosmultiple01 may 2017
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RIESGO
abrir
GitHub PoC29
From SQL injection to root shell with CVE-2016-6662 by MaYaSeVeN
CVE-2016-666201 may 2017
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir
Exploit-DBVexDay Proof
Tuleap Project Wiki 8.3 < 9.6.99.86 - Command Injection
CVE-2017-7981webappsphp01 may 2017
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project W
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque30 abr 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC4
Shellshock POC | CVE-2014-6271 | cgi-bin reverse shell
CVE-2014-6271CRITICALbajo ataque30 abr 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Admidio 3.2.8 - Cross-Site Request Forgery
CVE-2017-8382webappsphp28 abr 2017
admidio 3.2.8 has CSRF in adm_program/modules/members/members_function.php with an impact of deleting arbitrary user acc
23RIESGO
abrir
Metasploit600
Ghostscript Type Confusion Arbitrary Command Execution
CVE-2017-8291HIGHbajo ataque27 abr 2017
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir
GitHub PoC
A rebuilt version of the exploit for CVE-2016-1542 and CVE-2016-1543 from insinuator.net
CVE-2016-154227 abr 2017
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11.576.14393.0 - 'CStyleSheetArray::BuildListOfMatchedRules' Memory Corruption
CVE-2017-0202doswindows27 abr 2017
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
35RIESGO
abrir
GitHub PoC83
CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002
CVE-2018-199900226 abr 2017
A arbitrary file read vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framewor
45RIESGO
abrir
GitHub PoC83
CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002
CVE-2020-801226 abr 2017
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi
60RIESGO
abrir
GitHub PoC83
CVE-2020-8012, CVE-2016-10709, CVE-2017-17099, CVE-2017-18047, CVE-2019-1003000, CVE-2018-1999002
CVE-2019-100300026 abr 2017
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
Metasploit600
Symantec Messaging Gateway Remote Code Execution
CVE-2017-632626 abr 2017
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an i
60RIESGO
abrir
Metasploit600
Jenkins CLI Deserialization
CVE-2017-1000353CRITICALbajo ataque26 abr 2017
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RIESGO
abrir
Metasploit600
October CMS Upload Protection Bypass Code Execution
CVE-2017-100011925 abr 2017
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise
50RIESGO
abrir
Exploit-DB
Oracle E-Business Suite 12.2.3 - 'IESFOOTPRINT' SQL Injection
CVE-2017-3549webappsjsp25 abr 2017
Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Sup
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple Safari - Array concat Memory Corruption
CVE-2017-2464dosmultiple25 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Exploit-DBVexDay Proof
Realtek Audio Driver 6.0.1.7898 (Windows 10) - Dolby Audio X2 Service Privilege Escalation
CVE-2017-7293localwindows25 abr 2017
The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to
23RIESGO
abrir
anteriorpágina 975 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.