Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Dell EMC Isilon OneFS - Multiple Vulnerabilities
CVE-2018-120114 feb 2018
Dell EMC Isilon versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, and vers
23RIESGO
abrir
Exploit-DB
Dell EMC Isilon OneFS - Multiple Vulnerabilities
CVE-2018-121314 feb 2018
Dell EMC Isilon OneFS versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, versions 7.2.1.x, an
23RIESGO
abrir
Exploit-DB
TypeSetter CMS 5.1 - 'Host' Header Injection
CVE-2018-688913 feb 2018
An issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a m
23RIESGO
abrir
Exploit-DB
CloudMe Sync < 1.11.0 - Buffer Overflow
CVE-2018-689213 feb 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
Exploit-DB
Advantech WebAccess 8.3.0 - Remote Code Execution
CVE-2018-691113 feb 2018
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS
28RIESGO
abrir
Exploit-DB
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
CVE-2010-385612 feb 2018
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RIESGO
abrir
Exploit-DB
glibc - '$ORIGIN' Expansion Privilege Escalation (Metasploit)
CVE-2010-384712 feb 2018
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RIESGO
abrir
Exploit-DB
Juju-run Agent - Privilege Escalation (Metasploit)
CVE-2017-923212 feb 2018
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate pe
50RIESGO
abrir
Exploit-DB
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
CVE-2010-384712 feb 2018
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RIESGO
abrir
Exploit-DB
LibreOffice < 6.0.1 - '=WEBSERVICE' Remote Arbitrary File Disclosure
CVE-2018-687110 feb 2018
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a
28RIESGO
abrir
Exploit-DB
macOS Kernel - Use-After-Free Due to Lack of Locking in 'AppleEmbeddedOSSupportHostClient::registerNotificationPort'
CVE-2018-408309 feb 2018
An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar S
23RIESGO
abrir
Exploit-DB
Cisco ASA - Crash (PoC)
CVE-2018-010107 feb 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RIESGO
abrir
Exploit-DB
Asterisk 13.17.2 - 'chan_skinny' Remote Memory Corruption
CVE-2017-1709007 feb 2018
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and old
45RIESGO
abrir
Exploit-DB
Adobe Coldfusion 11.0.03.292866 - BlazeDS Java Object Deserialization Remote Code Execution
CVE-2017-3066CRITICALbajo ataque07 feb 2018
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir
Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Privilege Escalation
CVE-2018-660607 feb 2018
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RIESGO
abrir
Exploit-DB
Joomla! Component Zh GoogleMap 8.4.0.0 - SQL Injection
CVE-2018-658205 feb 2018
SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, ge
23RIESGO
abrir
Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Local Privilege Escalation
CVE-2018-659305 feb 2018
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RIESGO
abrir
Exploit-DB
Wonder CMS 2.3.1 - 'Host' Header Injection
CVE-2017-1452305 feb 2018
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NO
23RIESGO
abrir
Exploit-DB
Apport/ABRT - 'chroot' Local Privilege Escalation (Metasploit)
CVE-2015-131805 feb 2018
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RIESGO
abrir
Exploit-DB
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0147HIGHbajo ataqueransomware05 feb 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DB
Claymore Dual GPU Miner 10.5 - Format String
CVE-2018-631705 feb 2018
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format strin
50RIESGO
abrir
Exploit-DB
Wonder CMS 2.3.1 - Unrestricted File Upload
CVE-2017-1452105 feb 2018
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0143HIGHbajo ataqueransomware05 feb 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DB
HPE iLO 4 < 2.53 - Add New Administrator User
CVE-2017-1254205 feb 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir
Exploit-DB
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0146HIGHbajo ataqueransomware05 feb 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DB
Netis WF2419 Router - Cross-Site Scripting
CVE-2018-619005 feb 2018
Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.
23RIESGO
abrir
Exploit-DB
Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection
CVE-2018-660505 feb 2018
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get
50RIESGO
abrir
Exploit-DB
WordPress Core - 'load-scripts.php' Denial of Service
CVE-2018-638905 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
Exploit-DB
Online Voting System - Authentication Bypass
CVE-2018-618005 feb 2018
A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password fo
23RIESGO
abrir
Exploit-DB
Joomla! Component Zh YandexMap 6.2.1.0 - 'id' SQL Injection
CVE-2018-660405 feb 2018
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail
23RIESGO
abrir
anteriorpágina 105 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.