Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Crypttech CryptoLog Remote Code Execution
CVE-2025-34102CRITICAL03 may 2017
CryptoLog Unauthenticated RCE via SQL Injection and Command Injection
63RIESGO
abrir
Metasploit600
Serviio Media Server checkStreamUrl Command Execution
CVE-2025-34101CRITICAL03 may 2017
Serviio Media Server Unauthenticated Command Injection via checkStreamUrl VIDEO Parameter
63RIESGO
abrir
Metasploit200
WordPress PHPMailer Host Header Command Injection
CVE-2016-10033CRITICALbajo ataque03 may 2017
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
Metasploit600
Ghostscript Type Confusion Arbitrary Command Execution
CVE-2017-8291HIGHbajo ataque27 abr 2017
Artifex Ghostscript through 2017-04-26 allows -dSAFER bypass and remote command execution via .rsdparams type confusion
100RIESGO
abrir
Metasploit600
Jenkins CLI Deserialization
CVE-2017-1000353CRITICALbajo ataque26 abr 2017
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RIESGO
abrir
Metasploit600
Symantec Messaging Gateway Remote Code Execution
CVE-2017-632626 abr 2017
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an i
60RIESGO
abrir
Metasploit600
October CMS Upload Protection Bypass Code Execution
CVE-2017-100011925 abr 2017
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise
50RIESGO
abrir
Metasploit600
Solaris 'EXTREMEPARR' dtappgather Privilege Escalation
CVE-2017-362224 abr 2017
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (C
38RIESGO
abrir
Metasploit600
WePresent WiPG-1000 Command Injection
CVE-2025-34103CRITICAL20 abr 2017
WePresent WiPG-1000 Unauthenticated Command Injection in via rdfs.cgi
63RIESGO
abrir
Metasploit600
Mercurial Custom hg-ssh Wrapper Remote Code Exec
CVE-2017-946218 abr 2017
In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and conse
23RIESGO
abrir
Metasploit300
MantisBT password reset
CVE-2017-761516 abr 2017
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0147HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0144HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0146HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0148HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit600
Microsoft Office Word Malicious Hta Execution
CVE-2017-0199HIGHbajo ataqueransomware14 abr 2017
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0143HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit500
SMB DOUBLEPULSAR Remote Code Execution
CVE-2017-0145HIGHbajo ataqueransomware14 abr 2017
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Metasploit600
Juju-run Agent Privilege Escalation
CVE-2017-923213 abr 2017
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate pe
50RIESGO
abrir
Metasploit600
Trend Micro Threat Discovery Appliance admin_sys_time.cgi Remote Command Execution
CVE-2016-755210 abr 2017
On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows
40RIESGO
abrir
Metasploit600
Trend Micro Threat Discovery Appliance admin_sys_time.cgi Remote Command Execution
CVE-2016-754710 abr 2017
A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in
40RIESGO
abrir
Metasploit300
Quest Privilege Manager pmmasterd Buffer Overflow
CVE-2017-655309 abr 2017
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full
50RIESGO
abrir
Metasploit300
Satel Iberia SenNet Data Logger and Electricity Meters Command Injection Vulnerability
CVE-2017-604807 abr 2017
A Command Injection issue was discovered in Satel Iberia SenNet Data Logger and Electricity Meters: SenNet Optimal DataL
23RIESGO
abrir
Metasploit400
MediaWiki SyntaxHighlight extension option injection vulnerability
CVE-2017-037206 abr 2017
Parameters injection in SyntaxHighlight results in multiple vulnerabilities
23RIESGO
abrir
Metasploit300
TYPO3 News Module SQL Injection
CVE-2017-758106 abr 2017
SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated
30RIESGO
abrir
Metasploit300
HP Jetdirect Path Traversal Arbitrary Code Execution
CVE-2017-274105 abr 2017
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RIESGO
abrir
Metasploit300
Sync Breeze Enterprise 9.5.16 - Import Command Buffer Overflow
CVE-2017-731029 mar 2017
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RIESGO
abrir
Metasploit400
AF_PACKET packet_set_ring Privilege Escalation
CVE-2017-730829 mar 2017
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RIESGO
abrir
Metasploit300
Dup Scout Enterprise v10.4.16 - Import Command Buffer Overflow
CVE-2017-731029 mar 2017
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RIESGO
abrir
Metasploit0
Microsoft IIS WebDav ScStoragePathFromUrl Overflow
CVE-2017-7269CRITICALbajo ataque26 mar 2017
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.