Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
WebKit - 'WebCore::Node::getFlag' Use-After-Free
CVE-2017-7041dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderSearchField::addSearchResult' Heap Buffer Overflow
CVE-2017-7049dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::AccessibilityNodeObject::textUnderElement' Use-After-Free
CVE-2017-7048dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::getCachedWrapper' Use-After-Free
CVE-2017-7040dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::InputType::element' Use-After-Free (1)
CVE-2017-7042dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::AccessibilityRenderObject::handleAriaExpandedChanged' Use-After-Free
CVE-2017-7043dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::Node::nextSibling' Use-After-Free
CVE-2017-7039dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
Razer Synapse 2.20.15.1104 - rzpnk.sys ZwOpenProcess (Metasploit)
CVE-2017-9769localwindows_x86-6424 jul 2017
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderObject' with Accessibility Enabled Use-After-Free
CVE-2017-7046dosmultiple24 jul 2017
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'IOCTL 0x120007 NsiGetParameter' nsiproxy/netio Pool Memory Disclosure
CVE-2017-8564doswindows18 jul 2017
Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11.0.9600.18617 - 'CMarkup::DestroySplayTree' Memory Corruption
CVE-2017-8594doswindows18 jul 2017
Internet Explorer on Microsoft Windows 8.1 and Windows RT 8.1, and Windows Server 2012 R2 allows an attacker to execute
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11.1066.14393.0 - VBScript Arithmetic Functions Type Confusion
CVE-2017-8618doswindows18 jul 2017
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server
35RIESGO
abrir
Exploit-DBVexDay Proof
Sophos Web Appliance 4.3.0.2 - 'trafficType' Remote Command Injection (Metasploit)
CVE-2017-6182webappsjson18 jul 2017
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports wa
28RIESGO
abrir
Exploit-DBVexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection
CVE-2017-6972webappslinux11 jul 2017
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 have an error in privilege dropping and unnecessarily execu
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7/8.1/2008 R2/2012 R2/2016 R2 - 'EternalBlue' SMB Remote Code Execution (MS17-010)
CVE-2017-0144HIGHbajo ataqueransomwareremotewindows11 jul 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM 4.3.1 - 'customfmt' Command Injection
CVE-2017-7175webappslinux11 jul 2017
NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt pa
23RIESGO
abrir
Exploit-DBVexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM 5.3.4 - Command Injection
CVE-2017-6971webappslinux10 jul 2017
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary comma
28RIESGO
abrir
Exploit-DBVexDay Proof
NfSen < 1.3.7 / AlienVault OSSIM < 5.3.6 - Local Privilege Escalation
CVE-2017-6970locallinux10 jul 2017
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow local users to execute arbitrary commands in a privil
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts 2.3.x Showcase - Remote Code Execution
CVE-2017-9791CRITICALbajo ataquewebappsmultiple07 jul 2017
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
Exploit-DBVexDay Proof
LibTIFF - '_TIFFVGetField (tiffsplit)' Out-of-Bounds Read
CVE-2017-9147doslinux06 jul 2017
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cau
23RIESGO
abrir
Exploit-DBVexDay Proof
LibTIFF - 'tif_dirwrite.c' Denial of Service
CVE-2017-10688doslinux06 jul 2017
In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A
23RIESGO
abrir
Exploit-DBVexDay Proof
LibTIFF - 'tif_jbig.c' Denial of Service
CVE-2017-9936doslinux06 jul 2017
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a
23RIESGO
abrir
Exploit-DBVexDay Proof
GoAutoDial CE 3.3 - Authentication Bypass / Command Injection (Metasploit)
CVE-2015-2845remoteunix05 jul 2017
The cpanel function in go_site.php in GoAutoDial GoAdmin CE before 3.3-1421902800 allows remote attackers to execute arb
60RIESGO
abrir
Exploit-DBVexDay Proof
GoAutoDial CE 3.3 - Authentication Bypass / Command Injection (Metasploit)
CVE-2015-2843remoteunix05 jul 2017
Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute
50RIESGO
abrir
Exploit-DBVexDay Proof
Veritas/Symantec Backup Exec - SSL NDMP Connection Use-After-Free (Metasploit)
CVE-2017-8895remotewindows29 jun 2017
In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a u
60RIESGO
abrir
Exploit-DBVexDay Proof
ActiveMQ < 5.14.0 - Web Shell Upload (Metasploit)
CVE-2016-3088CRITICALbajo ataqueremotejava29 jun 2017
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel - 'offset2lib' Stack Clash
CVE-2017-1000371locallinux_x8628 jun 2017
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Debian 9/10 / Ubuntu 14.04.5/16.04.2/17.04 / Fedora 23/24/25) - 'ldso_dynamic Stack Clash' Local Privilege Escalation
CVE-2017-1000371locallinux_x8628 jun 2017
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Debian 7/8/9/10 / Fedora 23/24/25 / CentOS 5.3/5.11/6.0/6.8/7.2.1511) - 'ldso_hwcap Stack Clash' Local Privilege Escalation
CVE-2017-1000366locallinux_x8628 jun 2017
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causin
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Debian 7.7/8.5/9.0 / Ubuntu 14.04.2/16.04.2/17.04 / Fedora 22/25 / CentOS 7.3.1611) - 'ldso_hwcap_64 Stack Clash' Local Privilege Escalation
CVE-2017-1000379locallinux_x86-6428 jun 2017
The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.