Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Apple iOS 11.2.5 / watchOS 4.2.2 / tvOS 11.2.5 - 'bluetoothd' Memory Corruption
CVE-2018-4087dosmultiple28 feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RIESGO
abrir
Exploit-DBVexDay Proof
Asterisk chan_pjsip 15.2.0 - 'INVITE' Denial of Service
CVE-2018-7286doslinux27 feb 2018
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asteris
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.1/2012 R2 - SMBv3 Null Pointer Dereference Denial of Service
CVE-2018-0833doswindows27 feb 2018
The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2
35RIESGO
abrir
Exploit-DBVexDay Proof
Asterisk chan_pjsip 15.2.0 - 'SUBSCRIBE' Stack Corruption
CVE-2018-7284doslinux27 feb 2018
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce
35RIESGO
abrir
Exploit-DBVexDay Proof
CloudMe Sync 1.10.9 - Stack-Based Buffer Overflow (Metasploit)
CVE-2018-6892remotewindows26 feb 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
Exploit-DBVexDay Proof
AsusWRT LAN - Remote Code Execution (Metasploit)
CVE-2018-5999remotehardware26 feb 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro
60RIESGO
abrir
Exploit-DBVexDay Proof
AsusWRT LAN - Remote Code Execution (Metasploit)
CVE-2018-6000remotehardware26 feb 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn
60RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6227webappsjsp22 feb 2018
A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6226webappsjsp22 feb 2018
Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6221webappsjsp22 feb 2018
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6223webappsjsp22 feb 2018
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allo
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6225webappsjsp22 feb 2018
An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenti
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6228webappsjsp22 feb 2018
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to exe
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6229webappsjsp22 feb 2018
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6230webappsjsp22 feb 2018
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6220webappsjsp22 feb 2018
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbi
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6219webappsjsp22 feb 2018
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdr
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6224webappsjsp22 feb 2018
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could a
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6222webappsjsp22 feb 2018
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log fi
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - StorSvc SvcMoveFileInheritSecurity Arbitrary File Creation Privilege Escalation
CVE-2018-0826localwindows20 feb 2018
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, versi
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - 'Js::RegexHelper::RegexReplace' Use-After-Free
CVE-2018-0866doswindows20 feb 2018
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'nt!RtlpCopyLegacyContextX86' Stack Memory Disclosure
CVE-2018-0832doswindows20 feb 2018
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Window
23RIESGO
abrir
Exploit-DBVexDay Proof
MagniComp SysInfo - mcsiwrapper Privilege Escalation (Metasploit)
CVE-2017-6516localmultiple20 feb 2018
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NPFS Symlink Security Feature Bypass/Elevation of Privilege/Dangerous Behavior
CVE-2018-0823localwindows20 feb 2018
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Constrained Impersonation Capability Privilege Escalation
CVE-2018-0821localwindows20 feb 2018
AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Global Reparse Point Security Feature Bypass/Elevation of Privilege
CVE-2018-0822localwindows20 feb 2018
NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an eleva
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component JTicketing 2.0.16 - SQL Injection
CVE-2018-6585webappsphp16 feb 2018
SQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or fi
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component DT Register 3.2.7 - 'id' SQL Injection
CVE-2018-6584webappsphp16 feb 2018
SQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Gallery WD 1.3.6 - SQL Injection
CVE-2018-5981webappsphp16 feb 2018
SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
EPIC MyChart - X-Path Injection
CVE-2016-6272webappsasp16 feb 2018
XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing s
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.