Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.041exploits catalogados
36.286CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0120doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Color Management Module 'icm32.dll' - 'icm32!Fill_ushort_ELUTs_from_lut16Tag' Out-of-Bounds Read (MS17-013)
CVE-2017-0061doswindows20 mar 2017
The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2, Windows Server 2008 SP2 and
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Buffer Overflow in 'USP10!FillAlternatesList' (MS17-011)
CVE-2017-0072doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0115doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0112doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0114doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0121doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Heap Memory Corruption in 'USP10!otlCacheManager::GlyphsSubstituted' (MS17-011)
CVE-2017-0086doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Heap Memory Corruption in 'USP10!MergeLigRecords' (MS17-011)
CVE-2017-0087doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0122doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0118doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0119doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Multiple Heap Out-of-Bounds and Wild Reads (MS17-011)
CVE-2017-0117doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Uniscribe Font Processing Heap Buffer Overflow in 'USP10!ttoGetTableData' (MS17-011)
CVE-2017-0088doswindows20 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge 38.14393.0.0 - JavaScript Engine Use-After-Free
CVE-2017-0070doswindows16 mar 2017
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)
CVE-2017-0100localwindows15 mar 2017
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Thumbnailing Heap Overflow
CVE-2017-2933dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture co
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - MovieClip Attach init Object Use-After-Free
CVE-2017-2932dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript
28RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - 'Jakarta' Multipart Parser OGNL Injection (Metasploit)
CVE-2017-5638CRITICALbajo ataqueransomwareremotemultiple15 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Planar Decompression Heap Overflow
CVE-2017-2934dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Te
28RIESGO
abrir
Exploit-DBVexDay Proof
IBM WebSphere - RCE Java Deserialization (Metasploit)
CVE-2015-7450CRITICALbajo ataqueremotewindows15 mar 2017
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Metadata Parsing Out-of-Bounds Read
CVE-2017-2931dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the pa
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - AVC Header Slicing Heap Overflow
CVE-2017-2935dosmultiple15 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the F
28RIESGO
abrir
Exploit-DBVexDay Proof
Netgear R7000 / R6400 - 'cgi-bin' Command Injection (Metasploit)
CVE-2016-6277HIGHbajo ataqueremotecgi13 mar 2017
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RIESGO
abrir
Exploit-DBVexDay Proof
MobaXterm Personal Edition 9.4 - Directory Traversal
CVE-2017-6805remotewindows11 mar 2017
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read a
23RIESGO
abrir
Exploit-DBVexDay Proof
FTP Voyager Scheduler 16.2.0 - Cross-Site Request Forgery
CVE-2017-6803webappsxml10 mar 2017
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution
CVE-2017-5638CRITICALbajo ataqueransomwarewebappslinux07 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DBVexDay Proof
Azure Data Expert Ultimate 2.2.16 - Remote Buffer Overflow
CVE-2017-6506remotewindows07 mar 2017
In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leadi
28RIESGO
abrir
Exploit-DBVexDay Proof
FTPShell Client 6.53 - Remote Buffer Overflow
CVE-2017-6465remotewindows04 mar 2017
Remote Code Execution was discovered in FTPShell Client 6.53. By default, the client sends a PWD command to the FTP serv
50RIESGO
abrir
Exploit-DBVexDay Proof
Conext ComBox 865-1058 - Denial of Service
CVE-2017-6019doshardware02 mar 2017
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830
35RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.