Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.184exploits catalogados
37.029CVEs con explotación pública
24.695probados en laboratorio
80.184 exploits
VulnCheck XDB
initial-access
CVE-2022-0543CRITICALbajo ataque09 abr 2017
It was discovered, that redis, a persistent key-value database, due to a packaging issue, is prone to a (Debian-specific
100RIESGO
abrir
GitHub PoC10
Strutsy - Mass exploitation of Apache Struts (CVE-2017-5638) vulnerability
CVE-2017-5638CRITICALbajo ataqueransomware09 abr 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Metasploit300
Quest Privilege Manager pmmasterd Buffer Overflow
CVE-2017-655309 abr 2017
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full
50RIESGO
abrir
Metasploit300
Satel Iberia SenNet Data Logger and Electricity Meters Command Injection Vulnerability
CVE-2017-604807 abr 2017
A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataL
23RIESGO
abrir
Exploit-DB
Adobe (Multiple Products) - XML Injection File Content Disclosure
CVE-2009-3960MEDIUMbajo ataqueransomwarewebappsxml07 abr 2017
Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Service
100RIESGO
abrir
Exploit-DB
Intellinet NFC-30IR Camera - Multiple Vulnerabilities
CVE-2017-7461webappshardware07 abr 2017
Directory traversal vulnerability in the web-based management site on the Intellinet NFC-30ir IP Camera with firmware LM
28RIESGO
abrir
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6359webappscgi07 abr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and execute arbitrary commands vi
28RIESGO
abrir
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6360webappscgi07 abr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information
35RIESGO
abrir
Exploit-DB
Intellinet NFC-30IR Camera - Multiple Vulnerabilities
CVE-2017-7462webappshardware07 abr 2017
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI scr
28RIESGO
abrir
Exploit-DB
D-Link DWR-116 / DWR-116A1 - Arbitrary File Download
CVE-2017-6190webappshardware07 abr 2017
Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows
28RIESGO
abrir
Exploit-DBVexDay Proof
QNAP TVS-663 QTS < 4.2.4 build 20170313 - Command Injection
CVE-2017-6361webappscgi07 abr 2017
QNAP QTS before 4.2.4 Build 20170313 allows attackers to execute arbitrary commands via unspecified vectors.
35RIESGO
abrir
GitHub PoC5
Ruby Exploit for IIS 6.0 Buffer Overflow (CVE-2017-7269)
CVE-2017-7269CRITICALbajo ataque06 abr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
Exploit-DB
Cesanta Mongoose OS - Use-After-Free
CVE-2017-7185doshardware06 abr 2017
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embed
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque06 abr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
Exploit-DB
Moodle 2.x/3.x - SQL Injection
CVE-2017-2641webappsphp06 abr 2017
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
28RIESGO
abrir
Metasploit400
MediaWiki SyntaxHighlight extension option injection vulnerability
CVE-2017-037206 abr 2017
Parameters injection in SyntaxHighlight results in multiple vulnerabilities
23RIESGO
abrir
Metasploit300
TYPO3 News Module SQL Injection
CVE-2017-758106 abr 2017
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated
30RIESGO
abrir
Metasploit300
HP Jetdirect Path Traversal Arbitrary Code Execution
CVE-2017-274105 abr 2017
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RIESGO
abrir
Exploit-DB
D-Link DIR-615 - Cross-Site Request Forgery
CVE-2017-7398webappshardware05 abr 2017
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacke
23RIESGO
abrir
Exploit-DB
SpiceWorks 7.5 TFTP - Remote File Overwrite / Upload
CVE-2017-7237remotewindows05 abr 2017
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spicewor
23RIESGO
abrir
Exploit-DB
HelpDEZK 1.1.1 - Cross-Site Request Forgery / Code Execution
CVE-2017-7446webappsphp05 abr 2017
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
23RIESGO
abrir
GitHub PoC92
iis6 exploit 2017 CVE-2017-7269
CVE-2017-7269CRITICALbajo ataque05 abr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
Exploit-DB
HelpDEZK 1.1.1 - Cross-Site Request Forgery / Code Execution
CVE-2017-7447webappsphp05 abr 2017
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
23RIESGO
abrir
Exploit-DBVexDay Proof
Faveo Helpdesk Community 1.9.3 - Cross-Site Request Forgery
CVE-2017-7571webappsphp05 abr 2017
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque05 abr 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS Kernel 10.12.2 (16C67) - Memory Disclosure Due to Lack of Bounds Checking in AppleIntelCapriController::getDisplayPipeCapability
CVE-2017-2489dosmacos04 abr 2017
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple Webkit - 'JSCallbackData' Universal Cross-Site Scripting
CVE-2017-2442webappsmultiple04 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issu
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - HTMLInputElement Use-After-Free
CVE-2017-2454dosmultiple04 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS Kernel 10.12.2 (16C67) - 'AppleIntelCapriController::GetLinkConfig' Code Execution Due to Lack of Bounds Checking
CVE-2017-2443dosmacos04 abr 2017
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 (12602.3.12.0.1) - 'disconnectSubframes' Universal Cross-Site Scripting
CVE-2017-2445webappsmultiple04 abr 2017
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
anteriorpágina 979 / 2673siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.