Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DBVexDay Proof
Geutebruck 5.02024 G-Cam/EFD-2250 - 'testaction.cgi' Remote Command Execution (Metasploit)
CVE-2017-5174webappshardware15 feb 2017
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authenticatio
35RIESGO
abrir
Exploit-DB
F5 BIG-IP 11.6 SSL Virtual Server - 'Ticketbleed' Memory Disclosure
CVE-2016-9244remotehardware14 feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - TypedArray.sort Use-After-Free (MS16-145)
CVE-2016-7288doswindows14 feb 2017
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
45RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - Inter-process munmap in android.util.MemoryIntArray
CVE-2017-0411dosandroid14 feb 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
ntfs-3g - Unsanitized modprobe Environment Privilege Escalation
CVE-2017-0358HIGHlocallinux14 feb 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RIESGO
abrir
Exploit-DBVexDay Proof
Google Android - android.util.MemoryIntArray Ashmem Race Conditions
CVE-2017-0412dosandroid14 feb 2017
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RIESGO
abrir
GitHub PoC1
CVE-2017-2370
CVE-2017-237013 feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir
Metasploit300
Kodi 17.0 Local File Inclusion Vulnerability
CVE-2017-598212 feb 2017
Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files v
40RIESGO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS 7) - Denial of Service
CVE-2017-5972doslinux12 feb 2017
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RIESGO
abrir
GitHub PoC
CVE-2013-1775 Exploit written in Perl
CVE-2013-177511 feb 2017
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypas
38RIESGO
abrir
Exploit-DBVexDay Proof
HP Smart Storage Administrator 2.30.6.0 - Remote Command Injection (Metasploit)
CVE-2016-8523remotemultiple10 feb 2017
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
28RIESGO
abrir
GitHub PoC
Minion plugin for checking Ticketbleed (CVE-2016-9244)
CVE-2016-924410 feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RIESGO
abrir
GitHub PoC30
This is a tool for exploiting Ticketbleed (CVE-2016-9244) vulnerability.
CVE-2016-924410 feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RIESGO
abrir
Exploit-DB
F5 BIG-IP SSL Virtual Server - 'Ticketbleed' Memory Disclosure
CVE-2016-9244remotehardware10 feb 2017
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RIESGO
abrir
GitHub PoC1
CVE-2016-9079 exploit code as it appeared on https://lists.torproject.org/pipermail/tor-talk/2016-November/042639.html
CVE-2016-9079HIGHbajo ataque08 feb 2017
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
Exploit-DB
Node.JS - 'node-serialize' Remote Code Execution
CVE-2017-5941remotelinux08 feb 2017
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() fu
35RIESGO
abrir
VulnCheck XDB
client-side
CVE-2016-9079HIGHbajo ataque08 feb 2017
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
Exploit-DB
OpenBSD HTTPd < 6.0 - Memory Exhaustion Denial of Service
CVE-2017-5850dosopenbsd07 feb 2017
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RIESGO
abrir
Metasploit600
Piwik Superuser Plugin Upload
CVE-2025-34104CRITICAL05 feb 2017
Piwik Authenticated RCE via Custom Plugin Upload
43RIESGO
abrir
GitHub PoC4
paralelo14/CVE-2015-1579
CVE-2015-157903 feb 2017
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir
Metasploit300
Postfixadmin Protected Alias Deletion Vulnerability
CVE-2017-593003 feb 2017
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected al
23RIESGO
abrir
Exploit-DB
CUPS < 2.0.3 - Remote Command Execution
CVE-2015-1158remotelinux03 feb 2017
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-va
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-157903 feb 2017
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir
GitHub PoC4
dmonst3r/CVE-2015-1579
CVE-2015-157903 feb 2017
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RIESGO
abrir
Exploit-DB
ntfs-3g (Debian 9) - Local Privilege Escalation
CVE-2017-0358HIGHlocallinux03 feb 2017
ntfs-3g: Modprobe influence vulnerability via environment variables
56RIESGO
abrir
GitHub PoC5
Go Exploit for CVE-2011-4862
CVE-2011-486202 feb 2017
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RIESGO
abrir
GitHub PoC
Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2)
CVE-2017-237002 feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2011-486202 feb 2017
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'HTMLFormElement::reset()' Use-After Free
CVE-2017-2362dososx01 feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple WebKit - 'HTMLKeygenElement' Type Confusion
CVE-2017-2369dosmultiple01 feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir
anteriorpágina 991 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.