Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - 'FrameLoader::clear' Universal Cross-Site Scripting
CVE-2017-2363webappsmacos24 feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit 10.0.2 - 'Frame::setDocument' Universal Cross-Site Scripting
CVE-2017-2365webappsmultiple24 feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS HelpViewer 10.12.1 - XSS Leads to Arbitrary File Execution / Arbitrary File Read
CVE-2017-2361remotemacos23 feb 2017
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Help Viewer
28RIESGO
abrir
GitHub PoC1
A brief report on CVE-2016-4117 (A vulnerability in Adobe Flash)
CVE-2016-4117HIGHbajo ataqueransomware23 feb 2017
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RIESGO
abrir
Exploit-DB
EasyCom For PHP 4.0.0 - Buffer Overflow (PoC)
CVE-2017-5358doswindows22 feb 2017
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbi
28RIESGO
abrir
Exploit-DB
D-Link DCS Series Cameras - Insecure Crossdomain
CVE-2017-7852webappshardware22 feb 2017
D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access
23RIESGO
abrir
Exploit-DB
EasyCom For PHP 4.0.0 - Denial of Service
CVE-2017-5359doswindows22 feb 2017
EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.
23RIESGO
abrir
Exploit-DB
Disk Savvy Enterprise 9.4.18 - Remote Buffer Overflow (SEH)
CVE-2017-6187remotewindows22 feb 2017
Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary c
50RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - YUVPlane Decoding Heap Overflow
CVE-2017-2986dosmultiple21 feb 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability in the Flash Video (F
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Use-After-Free in Applying Bitmap Filter
CVE-2017-2985dosmultiple21 feb 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable use after free vulnerability in the ActionScript
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - MP4 AMF Parsing Overflow
CVE-2017-2992dosmultiple21 feb 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable heap overflow vulnerability when parsing an MP4 h
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - SWF Stack Corruption
CVE-2017-2988dosmultiple21 feb 2017
Adobe Flash Player versions 24.0.0.194 and earlier have an exploitable memory corruption vulnerability when performing g
28RIESGO
abrir
GitHub PoC
不完美的利用代码,只能用于学习:)
CVE-2016-466921 feb 2017
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RIESGO
abrir
GitHub PoC
Proof of concept exploit for CVE-2012-1723
CVE-2012-1723CRITICALbajo ataqueransomware20 feb 2017
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 up
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2012-1723CRITICALbajo ataqueransomware20 feb 2017
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 up
100RIESGO
abrir
Exploit-DB
WordPress Plugin Mail Masta 1.0 - SQL Injection
CVE-2017-6095webappsphp18 feb 2017
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list
23RIESGO
abrir
Exploit-DB
Sawmill Enterprise 8.7.9 - Authentication Bypass
CVE-2017-5496webappswindows18 feb 2017
Sawmill Enterprise 8.7.9 allows remote attackers to gain login access by leveraging knowledge of a password hash.
23RIESGO
abrir
Exploit-DB
WordPress Plugin Mail Masta 1.0 - SQL Injection
CVE-2017-6097webappsphp18 feb 2017
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/camp
23RIESGO
abrir
Exploit-DB
Netgear DGN2200v1/v2/v3/v4 - 'ping.cgi' Remote Command Execution
CVE-2017-6077CRITICALbajo ataquewebappshardware18 feb 2017
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitra
90RIESGO
abrir
Exploit-DB
WordPress Plugin Mail Masta 1.0 - SQL Injection
CVE-2017-6096webappsphp18 feb 2017
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/list
23RIESGO
abrir
Exploit-DB
WordPress Plugin Mail Masta 1.0 - SQL Injection
CVE-2017-6098webappsphp18 feb 2017
A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/camp
23RIESGO
abrir
Exploit-DBVexDay Proof
Artifex MuPDF mujstest 1.10a - Null Pointer Dereference
CVE-2017-6060doslinux17 feb 2017
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
dotCMS 3.6.1 - Blind Boolean SQL Injection
CVE-2017-5344webappsphp16 feb 2017
An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessib
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver 375.70 - Buffer Overflow in Command Buffer Submission
CVE-2017-0313doswindows15 feb 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) implem
23RIESGO
abrir
Exploit-DBVexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-5174webappshardware15 feb 2017
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
35RIESGO
abrir
Exploit-DB
OpenText Documentum D2 - Remote Code Execution
CVE-2017-5586remotejava15 feb 2017
OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a craf
28RIESGO
abrir
Exploit-DBVexDay Proof
Cisco ASA - WebVPN CIFS Handling Buffer Overflow
CVE-2017-3807doshardware15 feb 2017
A vulnerability in Common Internet Filesystem (CIFS) code in the Clientless SSL VPN functionality of Cisco ASA Software,
28RIESGO
abrir
Exploit-DBVexDay Proof
GOM Player 2.3.10.5266 - '.fpx' Denial of Service
CVE-2017-5881doswindows15 feb 2017
GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspeci
23RIESGO
abrir
Exploit-DBVexDay Proof
NVIDIA Driver 375.70 - DxgkDdiEscape 0x100008b Out-of-Bounds Read/Write
CVE-2017-0312doswindows15 feb 2017
All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handle
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' EMR_SETDIBITSTODEVICE Heap Out-of-Bounds Reads / Memory Disclosure
CVE-2017-0038doswindows15 feb 2017
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RIESGO
abrir
anteriorpágina 990 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.