Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.324exploits catalogados
37.130CVEs con explotación pública
24.695probados en laboratorio
80.324 exploits
Exploit-DBVexDay Proof
Apple WebKit - Type Confusion in RenderBox with Accessibility Enabled
CVE-2017-2373dosmultiple01 feb 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir
Metasploit300
WordPress REST API Content Injection
CVE-2017-100100001 feb 2017
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in Wor
40RIESGO
abrir
Metasploit600
AlienVault OSSIM/USM Remote Code Execution
CVE-2016-858231 ene 2017
A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbit
50RIESGO
abrir
Exploit-DB
AlienVault OSSIM/USM < 5.3.1 - Remote Code Execution (Metasploit)
CVE-2016-8580webappsphp31 ene 2017
PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vuln
23RIESGO
abrir
Exploit-DBVexDay Proof
Netgear Routers - Password Disclosure
CVE-2017-5521HIGHbajo ataquewebappshardware30 ene 2017
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RIESGO
abrir
Exploit-DB
PHP PEAR 1.10.1 - Arbitrary File Download
CVE-2017-5630webappsphp30 ene 2017
PECL in the download utility class in the Installer in PEAR Base System v1.10.1 does not validate file types and filenam
28RIESGO
abrir
GitHub PoC
OpenSSL CVE-2017-3730 proof-of-concept
CVE-2017-373030 ene 2017
Bad (EC)DHE parameters cause a client crash
35RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALbajo ataque28 ene 2017
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
GitHub PoC
CVE-2015-1635
CVE-2015-1635CRITICALbajo ataque28 ene 2017
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
GitHub PoC
vagrant box exploiting cve-2016-0728
CVE-2016-072827 ene 2017
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
Exploit-DB
Oracle VM VirtualBox < 5.0.32 / < 5.1.14 - Local Privilege Escalation
CVE-2017-3316locallinux27 ene 2017
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions tha
23RIESGO
abrir
Exploit-DB
Radisys MRF - Command Injection
CVE-2016-10043webappscgi27 ene 2017
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RIESGO
abrir
Exploit-DB
OpenSSH 6.8 < 6.9 - 'PTY' Local Privilege Escalation
CVE-2015-6565locallinux26 ene 2017
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial
23RIESGO
abrir
GitHub PoC
Ian Beer's exploit for CVE-2017-2370 (kernel memory r/w on iOS 10.2) https://bugs.chromium.org/p/project-zero/issues/detail?id=1004
CVE-2017-237026 ene 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free
CVE-2017-2360dosmultiple26 ene 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
23RIESGO
abrir
Exploit-DB
OpenSSL 1.1.0 - Remote Client Denial of Service
CVE-2017-3730dosmultiple26 ene 2017
Bad (EC)DHE parameters cause a client crash
35RIESGO
abrir
Exploit-DBVexDay Proof
Palo Alto Networks Terminal Services Agent 7.0.3-13 - Integer Overflow
CVE-2017-5329localwindows26 ene 2017
Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger a
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
CVE-2017-2353dosmultiple26 ene 2017
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RIESGO
abrir
Metasploit600
Haraka SMTP Command Injection
CVE-2016-100028226 ene 2017
Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlie
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption
CVE-2017-2370dosmultiple26 ene 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir
GitHub PoC1
Proof of concept CVE-2016-2098
CVE-2016-209825 ene 2017
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
Metasploit600
Oracle Weblogic Server Deserialization RCE - RMI UnicastRef
CVE-2017-324825 ene 2017
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir
GitHub PoC
Pilou-Pilou/docker_CVE-2014-6271.
CVE-2014-6271CRITICALbajo ataque25 ene 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
Systemd 228 (SUSE 12 SP2 / Ubuntu Touch 15.04) - Local Privilege Escalation
CVE-2016-10156locallinux24 ene 2017
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd tim
23RIESGO
abrir
Metasploit300
Geutebrueck GCore - GCoreServer.exe Buffer Overflow RCE
CVE-2017-1151724 ene 2017
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)
CVE-2016-9079HIGHbajo ataqueremotewindows24 ene 2017
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
Exploit-DB
Geutebrueck GCore 1.3.8.42/1.4.2.37 - Remote Code Execution (Metasploit)
CVE-2017-11517remotewindows24 ene 2017
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RIESGO
abrir
Exploit-DBVexDay Proof
Oracle OpenJDK Runtime Environment 1.8.0_112-b15 - Java Serialization Denial Of Service
CVE-2017-3241dosmultiple23 ene 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RIESGO
abrir
Exploit-DB
NTOPNG 2.4 Web Interface - Cross-Site Request Forgery
CVE-2017-5473webappslinux22 ene 2017
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authenticati
23RIESGO
abrir
Exploit-DBVexDay Proof
PageKit 1.0.10 - Password Reset
CVE-2017-5594webappsphp21 ene 2017
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the reg
23RIESGO
abrir
anteriorpágina 992 / 2678siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.