Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
GNU binutils - 'rx_decode_opcode' Buffer Overflow
CVE-2017-9750doslinux19 jun 2017
opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers t
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'disassemble_bytes' Heap Overflow
CVE-2017-9746doslinux19 jun 2017
The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (b
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'ieee_object_p' Stack Buffer Overflow
CVE-2017-9748doslinux19 jun 2017
The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'aarch64_ext_ldst_reglist' Buffer Overflow
CVE-2017-9756doslinux19 jun 2017
The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a d
23RIESGO
abrir
Exploit-DBVexDay Proof
GNU binutils - 'print_insn_score16' Buffer Overflow
CVE-2017-9742doslinux19 jun 2017
The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of ser
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - arrayProtoFuncSplice does not Initialize all Indices
CVE-2017-6980dosmultiple16 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - JIT Optimization Check Failed in IntegerCheckCombiningPhase::handleBlock
CVE-2017-2547dosmultiple16 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
28RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - JSGlobalObject::haveABadTime Causes Type Confusions
CVE-2017-7005dosmultiple16 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'Intl.getCanonicalLocales' Heap Buffer Overflow
CVE-2017-6984dosmultiple16 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. iTun
23RIESGO
abrir
Exploit-DBVexDay Proof
GStreamer gst-plugins-bad Plugin - NULL Pointer Dereference
CVE-2016-9813doslinux12 jun 2017
The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of ser
23RIESGO
abrir
Exploit-DBVexDay Proof
VMware vSphere Data Protection 5.x/6.x - Java Deserialization
CVE-2017-4914remotemultiple10 jun 2017
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of th
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.3 / iOS < 10.3.2 - Userspace Entitlement Checking Race Condition
CVE-2017-7004localmultiple09 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. The
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS - Disk Arbitration Daemon Race Condition
CVE-2017-2533localmacos09 jun 2017
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "DiskArbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
VMware Workstation 12 Pro - Denial of Service
CVE-2017-4916doswindows08 jun 2017
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Succes
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel - 'ping' Local Denial of Service
CVE-2017-2671dosandroid07 jun 2017
The ping_unhash function in net/ipv4/ping.c in the Linux kernel through 4.10.8 is too late in obtaining a certain lock a
23RIESGO
abrir
Exploit-DBVexDay Proof
Artifex MuPDF - Null Pointer Dereference
CVE-2017-5991doslinux07 jun 2017
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function i
28RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 4.10.13 - 'keyctl_set_reqkey_keyring' Local Denial of Service
CVE-2017-7472doslinux07 jun 2017
The KEYS subsystem in the Linux kernel before 4.10.13 allows local users to cause a denial of service (memory consumptio
23RIESGO
abrir
Exploit-DBVexDay Proof
PuTTY < 0.68 - 'ssh_agent_channel_data' Integer Overflow Heap Corruption
CVE-2017-6542doslinux07 jun 2017
The ssh_agent_channel_data function in PuTTY before 0.68 allows remote attackers to have unspecified impact via a large
28RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 2.2.6 - IPv6 Dissector Denial of Service
CVE-2017-9353dosmultiple05 jun 2017
In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by vali
28RIESGO
abrir
Exploit-DBVexDay Proof
DNSTracer 1.8.1 - Buffer Overflow (PoC)
CVE-2017-9430doslinux05 jun 2017
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
Exploit-DBVexDay Proof
Subsonic 6.1.1 - XML External Entity Injection
CVE-2017-9355localwindows05 jun 2017
XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to
28RIESGO
abrir
Exploit-DBVexDay Proof
Subsonic 6.1.1 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2017-9414webappswindows05 jun 2017
Cross-site request forgery (CSRF) vulnerability in the Subscribe to Podcast feature in Subsonic 6.1.1 allows remote atta
28RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark 2.2.0 < 2.2.12 - ROS Dissector Denial of Service
CVE-2017-9347dosmultiple05 jun 2017
In Wireshark 2.2.0 to 2.2.6, the ROS dissector could crash with a NULL pointer dereference. This was addressed in epan/d
28RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'JSObject::ensureLength' ensureLengthSlow Check Failure
CVE-2017-2521doslinux01 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - Incorrect Check in emitPutDerivedConstructorToArrowFunctionContextScope
CVE-2017-2531dosmultiple01 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - CachedFrame does not Detach Openers Universal Cross-Site Scripting
CVE-2017-2528webappsmultiple01 jun 2017
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Remote Use-After-Free Due to Design Issue in GC Engine
CVE-2017-8540HIGHbajo ataquedoswindows30 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
93RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Use-After-Free via Saved Callers
CVE-2017-8541doswindows30 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
35RIESGO
abrir
Exploit-DBVexDay Proof
IBM Informix Dynamic Server / Informix Open Admin Tool - DLL Injection / Remote Code Execution / Heap Buffer Overflow
CVE-2017-1092webappswindows30 may 2017
IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system a
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft MsMpEng - Multiple Crashes While Scanning Malformed Files
CVE-2017-8537doswindows29 may 2017
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.