Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Safari - Proxy Object Type Confusion (Metasploit)
CVE-2018-4404HIGHremotemacos14 dic 2018
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improve
61RIESGO
abrir
Exploit-DBVexDay Proof
Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure (2)
CVE-2018-7691MEDIUMwebappsmultiple14 dic 2018
MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized Access
33RIESGO
abrir
Exploit-DBVexDay Proof
Fortify Software Security Center (SSC) 17.10/17.20/18.10 - Information Disclosure
CVE-2018-7690MEDIUMwebappsmultiple14 dic 2018
MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized Access
33RIESGO
abrir
Exploit-DBVexDay Proof
CyberLink LabelPrint 2.5 - Stack Buffer Overflow (Metasploit)
CVE-2017-14627localwindows13 dic 2018
Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) au
43RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JIT - Int32/Double Arrays can have Proxy Objects in the Prototype Chains
CVE-2018-4438dosmultiple13 dic 2018
A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue affe
23RIESGO
abrir
Exploit-DBVexDay Proof
ZTE ZXHN H168N - Improper Access Restrictions
CVE-2018-7358MEDIUMwebappshardware11 dic 2018
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper cha
55RIESGO
abrir
Exploit-DBVexDay Proof
ZTE ZXHN H168N - Improper Access Restrictions
CVE-2018-7357MEDIUMwebappshardware11 dic 2018
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper acc
55RIESGO
abrir
Exploit-DBVexDay Proof
XNU - POSIX Shared Memory Mappings have Incorrect Maximum Protection
CVE-2018-4435localmultiple11 dic 2018
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 1
23RIESGO
abrir
Exploit-DBVexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
CVE-2018-6755HIGHlocalwindows11 dic 2018
True Key (TK) Windows Client - Weak Directory Permission Vulnerability
41RIESGO
abrir
Exploit-DBVexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
CVE-2018-6756HIGHlocalwindows11 dic 2018
True Key (TK) Windows Client - Authentication Abuse vulnerability
41RIESGO
abrir
Exploit-DBVexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
CVE-2018-6757HIGHlocalwindows11 dic 2018
True Key (TK) Windows Client - Privilege Escalation vulnerability
41RIESGO
abrir
Exploit-DBVexDay Proof
HP Intelligent Management - Java Deserialization Remote Code Execution (Metasploit)
CVE-2017-12557remotewindows04 dic 2018
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and e
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
CVE-2018-8474doswindows04 dic 2018
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa
35RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - 'find_signature' Heap Out-of-Bounds Read
CVE-2018-19627dosmultiple04 dic 2018
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/v
28RIESGO
abrir
Exploit-DBVexDay Proof
VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
CVE-2018-8544doswindows30 nov 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
VBScript - 'rtFilter' Out-of-Bounds Read
CVE-2018-8552doswindows30 nov 2018
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which coul
35RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - BytecodeGenerator::hoistSloppyModeFunctionIfNecessary Does not Invalidate the 'ForInContext' Object
CVE-2018-4386dosmultiple29 nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JIT - 'ByteCodeParser::handleIntrinsicCall' Type Confusion
CVE-2018-4382dosmultiple29 nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)
CVE-2018-18955locallinux29 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RIESGO
abrir
Exploit-DBVexDay Proof
PHP imap_open - Remote Code Execution (Metasploit)
CVE-2018-19518remotelinux29 nov 2018
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RIESGO
abrir
Exploit-DBVexDay Proof
Mac OS X - libxpc MITM Privilege Escalation (Metasploit)
CVE-2018-4237localmacos29 nov 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
43RIESGO
abrir
Exploit-DBVexDay Proof
Unitrends Enterprise Backup - bpserverd Privilege Escalation (Metasploit)
CVE-2018-6329locallinux29 nov 2018
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC JIT - 'JSPropertyNameEnumerator' Type Confusion
CVE-2018-4416dosmultiple29 nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RIESGO
abrir
Exploit-DBVexDay Proof
Netgear Devices - (Unauthenticated) Remote Command Execution (Metasploit)
CVE-2016-1555CRITICALbajo ataqueremotehardware27 nov 2018
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear
100RIESGO
abrir
Exploit-DBVexDay Proof
Xorg X11 Server - SUID privilege escalation (Metasploit)
CVE-2018-14665localmultiple26 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DfMarshal Unsafe Unmarshaling Privilege Escalation
CVE-2018-8550localwindows20 nov 2018
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerabili
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux - Broken uid/gid Mapping for Nested User Namespaces
CVE-2018-18955locallinux16 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RIESGO
abrir
Exploit-DBVexDay Proof
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
CVE-2018-15768webappslinux14 nov 2018
Insecure MySQL Configuration Vulnerability
23RIESGO
abrir
Exploit-DBVexDay Proof
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
CVE-2018-15767webappslinux14 nov 2018
Improper Authorization Vulnerability
28RIESGO
abrir
Exploit-DBVexDay Proof
Evince 3.24.0 - Command Injection
CVE-2017-1000083doslinux13 nov 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.