Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DB
dnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site Scripting
CVE-2017-6526webappscgi10 mar 2017
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution throug
50RIESGO
abrir
Exploit-DB
dnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site Scripting
CVE-2017-6528webappscgi10 mar 2017
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/
23RIESGO
abrir
Exploit-DB
dnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site Scripting
CVE-2017-6527webappscgi10 mar 2017
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal att
50RIESGO
abrir
GitHub PoC25
S2-045 漏洞 POC-TOOLS CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware09 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware09 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 - Denial of Service
CVE-2017-6552doshardware09 mar 2017
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing
23RIESGO
abrir
Exploit-DB
Wireless IP Camera (P2P) WIFICAM - Remote Code Execution
CVE-2017-8224remotehardware08 mar 2017
Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET.
23RIESGO
abrir
Exploit-DB
Wireless IP Camera (P2P) WIFICAM - Remote Code Execution
CVE-2017-8225remotehardware08 mar 2017
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
50RIESGO
abrir
Metasploit300
DnaLIMS Directory Traversal
CVE-2017-652708 mar 2017
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal att
50RIESGO
abrir
Metasploit600
dnaLIMS Admin Module Command Execution
CVE-2017-652608 mar 2017
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution throug
50RIESGO
abrir
Exploit-DB
ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Remote Code Execution
CVE-2017-6548webappshardware08 mar 2017
Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC
28RIESGO
abrir
GitHub PoC
bongbongco/cve-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware08 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Session Stealing
CVE-2017-6549webappshardware08 mar 2017
Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W
23RIESGO
abrir
Exploit-DB
ASUSWRT RT-AC53 (3.0.0.4.380.6038) - Cross-Site Scripting
CVE-2017-6547webappshardware08 mar 2017
Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC
23RIESGO
abrir
Exploit-DB
Wireless IP Camera (P2P) WIFICAM - Remote Code Execution
CVE-2017-8222remotehardware08 mar 2017
Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate st
23RIESGO
abrir
Exploit-DB
Wireless IP Camera (P2P) WIFICAM - Remote Code Execution
CVE-2017-8223remotehardware08 mar 2017
On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streamin
23RIESGO
abrir
Exploit-DB
Wireless IP Camera (P2P) WIFICAM - Remote Code Execution
CVE-2017-8221remotehardware08 mar 2017
Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communicati
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware08 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
iBall Baton 150M Wireless Router - Authentication Bypass
CVE-2017-6558webappsphp07 mar 2017
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vuln
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware07 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Metasploit300
Easy File Sharing FTP Server 3.6 Directory Traversal
CVE-2017-651007 mar 2017
Easy File Sharing FTP Server version 3.6 is vulnerable to a directory traversal vulnerability which allows an attacker t
23RIESGO
abrir
Metasploit600
Apache Struts Jakarta Multipart Parser OGNL Injection
CVE-2017-5638CRITICALbajo ataqueransomware07 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
Evostream Media Server 1.7.1 (x64) - Denial of Service
CVE-2017-6427doswindows_x86-6407 mar 2017
A Buffer Overflow was discovered in EvoStream Media Server 1.7.1. A crafted HTTP request with a malicious header will ca
23RIESGO
abrir
GitHub PoC23
Struts2 S2-045(CVE-2017-5638)Vulnerability environment - http://www.mottoin.com/97954.html
CVE-2017-5638CRITICALbajo ataqueransomware07 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution
CVE-2017-5638CRITICALbajo ataqueransomwarewebappslinux07 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC61
Struts2 S2-045(CVE-2017-5638)Exp with GUI
CVE-2017-5638CRITICALbajo ataqueransomware07 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DBVexDay Proof
Azure Data Expert Ultimate 2.2.16 - Remote Buffer Overflow
CVE-2017-6506remotewindows07 mar 2017
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leadi
28RIESGO
abrir
Exploit-DB
USBPcap 1.1.0.0 (WireShark 2.2.5) - Local Privilege Escalation
CVE-2017-6178localwindows07 mar 2017
The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call,
23RIESGO
abrir
Exploit-DB
Deluge Web UI 1.3.13 - Cross-Site Request Forgery
CVE-2017-7178webappsjson06 mar 2017
CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted p
23RIESGO
abrir
Exploit-DB
MikroTik Router - ARP Table OverFlow Denial Of Service
CVE-2017-6444doshardware05 mar 2017
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast netw
28RIESGO
abrir
anteriorpágina 988 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.