Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'BailOutOnTaggedValue' Bailouts Type Confusion
CVE-2017-11839doswindows27 nov 2017
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows a
35RIESGO
abrir
Exploit-DBVexDay Proof
ZTE ZXDSL 831CII - Improper Access Restrictions
CVE-2017-16953webappshardware27 nov 2017
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Incorrect Function Declaration Scope
CVE-2017-11870doswindows27 nov 2017
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'GlobOpt::OptTagChecks' Must Consider IsLoopPrePass Properly
CVE-2017-11840doswindows27 nov 2017
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'Inline::InlineCallApplyTarget_Shared' does not Return the return Instruction
CVE-2017-11841doswindows27 nov 2017
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RIESGO
abrir
Exploit-DBVexDay Proof
Exim 4.89 - 'BDAT' Denial of Service
CVE-2017-16944dosmultiple27 nov 2017
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial
35RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel - 'mincore()' Uninitialized Kernel Heap Page Disclosure
CVE-2017-16994doslinux24 nov 2017
The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, w
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderText::localCaretRect' Out-of-Bounds Read
CVE-2017-13785dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::TreeScope::documentScope' Use-After-Free
CVE-2017-13796dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::DocumentLoader::frameLoader' Use-After-Free
CVE-2017-13794dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::InputType::element' Use-After-Free (2)
CVE-2017-13792dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::FormSubmission::create' Use-After-Free
CVE-2017-13791dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::Style::TreeResolver::styleForElement' Use-After-Free
CVE-2017-13802dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderObject::previousSibling' Use-After-Free
CVE-2017-13798dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGPatternElement::collectPatternAttributes' Out-of-Bounds Read
CVE-2017-13783dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::SimpleLineLayout::RunResolver::runForPoint' Out-of-Bounds Read
CVE-2017-13784dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::AXObjectCache::performDeferredCacheUpdate' Use-After-Free
CVE-2017-13795dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::PositionIterator::decrement' Use-After-Free
CVE-2017-13797dosmultiple22 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - 'nt!NtQueryDirectoryFile (luafv!LuafvCopyDirectoryEntry)' Pool Memory Disclosure
CVE-2017-11831doswindows21 nov 2017
Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2,
23RIESGO
abrir
Exploit-DBVexDay Proof
iOS < 11.1 / tvOS < 11.1 / watchOS < 4.1 - Denial of Service
CVE-2017-13849dosios20 nov 2017
An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS be
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - CiSetFileCache TOCTOU Security Feature Bypass
CVE-2017-11830localwindows20 nov 2017
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allow
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Type Confusion with switch Statements
CVE-2017-11811doswindows16 nov 2017
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - 'Object.setPrototypeOf' Memory Corruption
CVE-2017-8751doswindows16 nov 2017
Microsoft Edge in Microsoft Windows 1703 allows an attacker to execute arbitrary code in the context of the current user
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra: JIT - 'Lowerer::LowerBoundCheck' Incorrect Integer Overflow Check
CVE-2017-11861doswindows16 nov 2017
Microsoft Edge in Windows 10 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker t
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra: JIT - 'OP_Memset' Type Confusion
CVE-2017-11873doswindows16 nov 2017
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709
35RIESGO
abrir
Exploit-DBVexDay Proof
Zeta Components Mail 1.8.1 - Remote Code Execution
CVE-2017-15806webappsphp16 nov 2017
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the s
28RIESGO
abrir
Exploit-DBVexDay Proof
D-Link DIR-605L < 2.08 - Denial of Service
CVE-2017-9675doshardware14 nov 2017
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
28RIESGO
abrir
Exploit-DBVexDay Proof
Kirby CMS < 2.5.7 - Cross-Site Scripting
CVE-2017-16807webappsphp13 nov 2017
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exist
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB 1.8.13 - Cross-Site Scripting
CVE-2017-16781webappsphp11 nov 2017
The installer in MyBB before 1.8.13 has XSS.
23RIESGO
abrir
Exploit-DBVexDay Proof
MyBB 1.8.13 - Remote Code Execution
CVE-2017-16780webappsphp11 nov 2017
The installer in MyBB before 1.8.13 allows remote attackers to execute arbitrary code by writing to the configuration fi
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.