Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.280exploits catalogados
37.122CVEs con explotación pública
24.695probados en laboratorio
80.285 exploits
Exploit-DB
DIGISOL DG-HR1400 1.00.02 Wireless Router - Privilege Escalation
CVE-2017-6896webappshardware18 mar 2017
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from
23RIESGO
abrir
Exploit-DB
Oracle Knowledge Management 12.1.1 < 12.2.5 - XML External Entity Leading To Remote Code Execution
CVE-2016-3542webappsmultiple17 mar 2017
Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3
23RIESGO
abrir
Metasploit300
Cisco IOS Telnet Denial of Service
CVE-2017-3881CRITICALbajo ataque17 mar 2017
A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software co
100RIESGO
abrir
Exploit-DB
Cisco IOS 12.2 < 12.4 / 15.0 < 15.6 - Security Association Negotiation Request Device Memory
CVE-2016-6415HIGHbajo ataqueremotehardware17 mar 2017
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RIESGO
abrir
Metasploit600
SolarWinds LEM Default SSH Password Remote Code Execution
CVE-2017-772217 mar 2017
In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is acce
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware17 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC3
Apache Struts (CVE-2017-5638) Shell
CVE-2017-5638CRITICALbajo ataqueransomware17 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
AXIS (Multiple Products) - Cross-Site Request Forgery
CVE-2015-8255webappshardware17 mar 2017
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
23RIESGO
abrir
Exploit-DB
AXIS Communications - Cross-Site Scripting / Content Injection
CVE-2015-8258webappshardware17 mar 2017
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via v
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.0.0 - JavaScript Engine Use-After-Free
CVE-2017-0070doswindows16 mar 2017
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
45RIESGO
abrir
GitHub PoC2
Struts2 RCE CVE-2017-5638 non-intrusive check shell script
CVE-2017-5638CRITICALbajo ataqueransomware16 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
Microsoft Windows DVD Maker 6.1.7 - XML External Entity Injection
CVE-2017-0045localwindows16 mar 2017
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse cr
23RIESGO
abrir
Exploit-DB
WordPress Plugin Membership Simplified 1.58 - Arbitrary File Download
CVE-2017-1002008webappsphp16 mar 2017
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membe
28RIESGO
abrir
Exploit-DB
Cerberus FTP Server 8.0.10.3 - 'MLST' Buffer Overflow (PoC)
CVE-2017-6880doswindows16 mar 2017
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or p
28RIESGO
abrir
Exploit-DB
CommVault Edge 11 SP6 - Stack Buffer Overflow (PoC)
CVE-2017-3195doswindows16 mar 2017
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware16 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC83
MS16-032(CVE-2016-0099) for SERVICE ONLY
CVE-2016-0099HIGHbajo ataqueransomware15 mar 2017
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - AVC Header Slicing Heap Overflow
CVE-2017-2935dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the F
28RIESGO
abrir
GitHub PoC14
cve-2017-5638 Vulnerable site sample
CVE-2017-5638CRITICALbajo ataqueransomware15 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)
CVE-2017-0100localwindows15 mar 2017
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM WebSphere - RCE Java Deserialization (Metasploit)
CVE-2015-7450CRITICALbajo ataqueremotewindows15 mar 2017
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-0099HIGHbajo ataqueransomware15 mar 2017
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RIESGO
abrir
Exploit-DB
Microsoft Windows - 'LoadUvsTable()' Heap Buffer Overflow
CVE-2016-7274doswindows15 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - MovieClip Attach init Object Use-After-Free
CVE-2017-2932dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript
28RIESGO
abrir
Exploit-DB
Sitecore CMS 8.1 Update-3 - Cross-Site Scripting
CVE-2016-8855webappsaspx15 mar 2017
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - 'Jakarta' Multipart Parser OGNL Injection (Metasploit)
CVE-2017-5638CRITICALbajo ataqueransomwareremotemultiple15 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Planar Decompression Heap Overflow
CVE-2017-2934dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Te
28RIESGO
abrir
Metasploit600
Github Enterprise Default Session Secret And Deserialization Vulnerability
CVE-2017-1836515 mar 2017
The Management Console in GitHub Enterprise 2.8.x before 2.8.7 has a deserialization issue that allows unauthenticated r
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Thumbnailing Heap Overflow
CVE-2017-2933dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture co
28RIESGO
abrir
Metasploit500
VX Search Enterprise GET Buffer Overflow
CVE-2017-1370815 mar 2017
Buffer overflow in the web server service in VX Search Enterprise 10.0.14 allows remote attackers to execute arbitrary c
23RIESGO
abrir
anteriorpágina 984 / 2677siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.