Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
GitHub PoC16
CVE-2017-0199
CVE-2017-0199HIGHbajo ataqueransomware19 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
GitHub PoC4
phpMyAdmin 3.3.X and 3.4.X - Local File Inclusion
CVE-2011-410719 abr 2017
The simplexml_load_string function in the XML import plug-in (libraries/import/xml.php) in phpMyAdmin 3.4.x before 3.4.7
28RIESGO
abrir
Exploit-DBVexDay Proof
Dmitry 1.3a - Local Buffer Overflow (PoC)
CVE-2017-7938MEDIUMdoslinux19 abr 2017
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau
33RIESGO
abrir
GitHub PoC
Exploit developed by me for CVE-2017-5633.
CVE-2017-563318 abr 2017
Multiple cross-site request forgery (CSRF) vulnerabilities on the D-Link DI-524 Wireless Router with firmware 9.01 allow
23RIESGO
abrir
GitHub PoC1
CVE-2011-3368 exploit code
CVE-2011-336818 abr 2017
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21 does
60RIESGO
abrir
Metasploit600
Mercurial Custom hg-ssh Wrapper Remote Code Exec
CVE-2017-946218 abr 2017
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and conse
23RIESGO
abrir
GitHub PoC23
Proof of concept exploit for CVE-2017-3599
CVE-2017-359918 abr 2017
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RIESGO
abrir
Exploit-DB
Tenable Appliance < 4.5 - Root Remote Code Execution
CVE-2017-8051remotelinux18 abr 2017
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI.
28RIESGO
abrir
Exploit-DB
Microsoft Word - '.RTF' Remote Code Execution
CVE-2017-0199HIGHbajo ataqueransomwareremotewindows18 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
GitHub PoC13
Quick and dirty fix to OLE2 executing code via .hta
CVE-2017-0199HIGHbajo ataqueransomware18 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0145HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0147HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC725
Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Office RCE. It could generate a malicious RTF/PPSX file and deliver metasploit / meterpreter / other payload to victim without any complex configuration.
CVE-2017-0199HIGHbajo ataqueransomware17 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0143HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0146HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0144HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Remote Code Execution Scanner (MS17-010) (Metasploit)
CVE-2017-0148HIGHbajo ataqueransomwaredoswindows17 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-0199HIGHbajo ataqueransomware17 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.3.0/2.3.0 - Password Reset
CVE-2017-7615webappsphp16 abr 2017
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RIESGO
abrir
Metasploit300
MantisBT password reset
CVE-2017-761516 abr 2017
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RIESGO
abrir
GitHub PoC2
homjxi0e/CVE-2017-0108
CVE-2017-010815 abr 2017
The Windows Graphics Component in Microsoft Office 2007 SP3; 2010 SP2; and Word Viewer; Skype for Business 2016; Lync 20
35RIESGO
abrir
Exploit-DB
Linux Kernel 4.8.0 UDEV < 232 - Local Privilege Escalation
CVE-2017-7874locallinux15 abr 2017
20RIESGO
abrir
GitHub PoC
homjxi0e/CVE-2016-7255
CVE-2016-7255HIGHbajo ataqueransomware15 abr 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
Exploit-DBVexDay Proof
Concrete5 CMS 8.1.0 - 'Host' Header Injection
CVE-2017-7725webappsphp14 abr 2017
concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a "ca
23RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0147HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0143HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0146HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0148HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0145HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0144HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
anteriorpágina 977 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.