Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Linux Kernel - 'offset2lib' Stack Clash
CVE-2017-1000370locallinux_x8628 jun 2017
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RIESGO
abrir
Exploit-DBVexDay Proof
NetBSD - 'Stack Clash' (PoC)
CVE-2017-1000375dosnetbsd_x8628 jun 2017
NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attacke
28RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Solaris 11.1/11.3 (RSH) - 'Stack Clash' Local Privilege Escalation
CVE-2017-3630localsolaris_x8628 jun 2017
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Solaris 11.1/11.3 (RSH) - 'Stack Clash' Local Privilege Escalation
CVE-2017-3629localsolaris_x8628 jun 2017
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir
Exploit-DBVexDay Proof
Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities
CVE-2017-9811webappslinux28 jun 2017
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maint
28RIESGO
abrir
Exploit-DBVexDay Proof
OpenBSD - 'at Stack Clash' Local Privilege Escalation
CVE-2017-1000373localopenbsd28 jun 2017
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N
28RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Debian 7.7/8.5/9.0 / Ubuntu 14.04.2/16.04.2/17.04 / Fedora 22/25 / CentOS 7.3.1611) - 'ldso_hwcap_64 Stack Clash' Local Privilege Escalation
CVE-2017-1000379locallinux_x86-6428 jun 2017
The Linux Kernel running on AMD64 systems will sometimes map the contents of PIE executable, the heap or ld.so to where
23RIESGO
abrir
Exploit-DBVexDay Proof
Kaspersky Anti-Virus File Server 8.0.3.297 - Multiple Vulnerabilities
CVE-2017-9813webappslinux28 jun 2017
In Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312), the scriptNa
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel - 'offset2lib' Stack Clash
CVE-2017-1000371locallinux_x8628 jun 2017
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Debian 9/10 / Ubuntu 14.04.5/16.04.2/17.04 / Fedora 23/24/25) - 'ldso_dynamic Stack Clash' Local Privilege Escalation
CVE-2017-1000371locallinux_x8628 jun 2017
The offset2lib patch as used by the Linux Kernel contains a vulnerability, if RLIMIT_STACK is set to RLIM_INFINITY and 1
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Debian 7/8/9/10 / Fedora 23/24/25 / CentOS 5.3/5.11/6.0/6.8/7.2.1511) - 'ldso_hwcap Stack Clash' Local Privilege Escalation
CVE-2017-1000370locallinux_x8628 jun 2017
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Debian 7/8/9/10 / Fedora 23/24/25 / CentOS 5.3/5.11/6.0/6.8/7.2.1511) - 'ldso_hwcap Stack Clash' Local Privilege Escalation
CVE-2017-1000366locallinux_x8628 jun 2017
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causin
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - 'setrlimit' Stack Clash (PoC)
CVE-2017-1085dosfreebsd_x8628 jun 2017
In FreeBSD before 11.2-RELEASE, an application which calls setrlimit() to increase RLIMIT_STACK may turn a read-only mem
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Debian 9/10 / Ubuntu 14.04.5/16.04.2/17.04 / Fedora 23/24/25) - 'ldso_dynamic Stack Clash' Local Privilege Escalation
CVE-2017-1000366locallinux_x8628 jun 2017
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causin
23RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - 'FGPE' Stack Clash (PoC)
CVE-2017-1084dosfreebsd_x8628 jun 2017
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections a
28RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - 'FGPU' Stack Clash (PoC)
CVE-2017-1084dosfreebsd_x8628 jun 2017
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections a
28RIESGO
abrir
Exploit-DBVexDay Proof
GLPI 0.90.4 - SQL Injection
CVE-2016-7508webappsphp27 jun 2017
Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL co
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - mpengine x86 Emulator Heap Corruption in VFS API
CVE-2017-8558doswindows27 jun 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on 32-bit versions of Micr
35RIESGO
abrir
Exploit-DBVexDay Proof
Symantec Messaging Gateway 10.6.2-7 - Remote Code Execution (Metasploit)
CVE-2017-6326remotepython26 jun 2017
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an i
60RIESGO
abrir
Exploit-DBVexDay Proof
LAME 3.99.5 - 'III_dequantize_sample' Stack Buffer Overflow
CVE-2017-9872doslinux26 jun 2017
The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products,
23RIESGO
abrir
Exploit-DBVexDay Proof
LAME 3.99.5 - 'II_step_one' Buffer Overflow
CVE-2017-9869doslinux26 jun 2017
The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows rem
23RIESGO
abrir
Exploit-DBVexDay Proof
Netgear DGN2200 - 'dnslookup.cgi' Command Injection (Metasploit)
CVE-2017-6334HIGHbajo ataqueremotecgi26 jun 2017
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'USP10!otlReverseChainingLookup::apply' Uniscribe Font Processing Out-of-Bounds Memory Read
CVE-2017-0288doswindows23 jun 2017
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'ATMFD.DLL' Out-of-Bounds Read due to Malformed Name INDEX in the CFF Table
CVE-2017-8483doswindows23 jun 2017
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'USP10!CreateIndexTable' Uniscribe Font Processing Out-of-Bounds Memory Read
CVE-2017-0282doswindows23 jun 2017
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryInformationWorkerFactory (WorkerFactoryBasicInformation)' Kernel Stack Memory Disclosure
CVE-2017-0300doswindows23 jun 2017
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Parser Heap Corruption
CVE-2017-3078dosmultiple23 jun 2017
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the Adobe Text
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Image Decoding Out-of-Bounds Read
CVE-2017-3077dosmultiple23 jun 2017
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'USP10!NextCharInLiga' Uniscribe Font Processing Out-of-Bounds Memory Read
CVE-2017-0286doswindows23 jun 2017
Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'USP10!ttoGetTableData' Uniscribe Font Processing Out-of-Bounds Memory Read
CVE-2017-0284doswindows23 jun 2017
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.