Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Qmail SMTP - Bash Environment Variable Injection (Metasploit)
CVE-2014-6271CRITICALbajo ataqueremotelinux02 oct 2017
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - Heap Overflow
CVE-2017-14492dosmultiple02 oct 2017
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir
Exploit-DBVexDay Proof
Dnsmasq < 2.78 - 2-byte Heap Overflow
CVE-2017-14491dosmultiple02 oct 2017
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Information Disclosure
CVE-2017-14085webappsphp28 sep 2017
Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can acc
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Man In The Middle Remote Code Execution
CVE-2017-14084remotewindows28 sep 2017
A potential Man-in-the-Middle (MitM) attack vulnerability in Trend Micro OfficeScan 11.0 and XG may allow attackers to e
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Code Execution / Memory Corruption
CVE-2017-14086webappswindows28 sep 2017
Pre-authorization Start Remote Process vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated u
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - Private Key Disclosure
CVE-2017-14083webappsphp28 sep 2017
A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to d
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 11.0/XG (12.0) - 'Host' Header Injection
CVE-2017-14087webappsphp28 sep 2017
A Host Header Injection vulnerability in Trend Micro OfficeScan XG (12.0) may allow an attacker to spoof a particular Ho
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Memory Read in MP4 Parsing
CVE-2017-11281dosmultiple25 sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Write in MP4 Edge Processing
CVE-2017-11281dosmultiple25 sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploita
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Read in applyToRange
CVE-2017-11282dosmultiple25 sep 2017
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation co
35RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS 10.2 - Broadcom Out-of-Bounds Write when Handling 802.11k Neighbor Report Response
CVE-2017-11120remoteios25 sep 2017
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RIESGO
abrir
Exploit-DBVexDay Proof
Supervisor 3.0a1 < 3.3.2 - XML-RPC (Authenticated) Remote Code Execution (Metasploit)
CVE-2017-11610remotelinux25 sep 2017
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir
Exploit-DBVexDay Proof
CyberLink LabelPrint < 2.5 - Local Buffer Overflow (SEH Unicode)
CVE-2017-14627localwindows23 sep 2017
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes
CVE-2017-8740doswindows21 sep 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'Parser::ParseCatch' Does Not Handle 'eval()' (Denial of Service)
CVE-2017-11764doswindows21 sep 2017
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptFunction::ReparseAsmJsModule' Incorrectly Re-parses
CVE-2017-8755doswindows21 sep 2017
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Chakra Incorrectly Parses Object Patterns
CVE-2017-8729doswindows21 sep 2017
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - Memory Corruption with Partial Page Loading
CVE-2017-8731doswindows19 sep 2017
Microsoft Edge in Microsoft Windows 10 1607 and Windows Server 2016 allows an attacker to execute arbitrary code in the
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.1066.0 - 'COptionsCollectionCacheItem::GetAt' Out-of-Bounds Read
CVE-2017-8734doswindows19 sep 2017
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arb
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetFontResourceInfoInternalW' Stack Memory Disclosure
CVE-2017-8684doswindows18 sep 2017
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtQueryCompositionSurfaceBinding' Stack Memory Disclosure
CVE-2017-8678doswindows18 sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetGlyphOutline' Pool Memory Disclosure
CVE-2017-8680doswindows18 sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiGetPhysicalMonitorDescription' Stack Memory Disclosure
CVE-2017-8681doswindows18 sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiDoBanding' Stack Memory Disclosure
CVE-2017-8687doswindows18 sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'nt!NtSetIoCompletion / nt!NtRemoveIoCompletion' Pool Memory Disclosure
CVE-2017-8708doswindows18 sep 2017
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' '.TTF' Font Processing Out-of-Bounds Reads/Writes with Malformed 'fpgm' table 'win32k!bGeneratePath' (Denial of Service)
CVE-2017-8682doswindows18 sep 2017
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' '.TTF' Font Processing Out-of-Bounds Read with Malformed 'glyf' Table 'win32k!fsc_CalcGrayRow' (Denial of Service)
CVE-2017-8683doswindows18 sep 2017
Windows graphics on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold a
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k!NtGdiEngCreatePalette' Stack Memory Disclosure
CVE-2017-8685doswindows18 sep 2017
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows information disclosure by the way
23RIESGO
abrir
Exploit-DBVexDay Proof
Infinite Automation Mango Automation - Command Injection (Metasploit)
CVE-2015-7901remotejsp13 sep 2017
Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execut
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.