Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.452exploits catalogados
36.587CVEs con explotación pública
24.695probados en laboratorio
79.386 exploits
Exploit-DBVexDay Proof
Netatalk 3.1.12 - Authentication Bypass (PoC)
CVE-2018-1160CRITICALdosmultiple21 dic 2018
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RIESGO
abrir
Exploit-DBVexDay Proof
VBScript - VbsErase Reference Leak Use-After-Free
CVE-2018-8625doswindows20 dic 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
VBScript - MSXML Execution Policy Bypass
CVE-2018-8619doswindows20 dic 2018
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest
35RIESGO
abrir
GitHub PoC5
Flash 2018-15982 UAF
CVE-2018-15982HIGHbajo ataqueransomware20 dic 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-10271HIGHbajo ataqueransomware20 dic 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC
Weblogic(CVE-2017-10271)
CVE-2017-10271HIGHbajo ataqueransomware20 dic 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2015-925120 dic 2018
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed wi
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12617HIGHbajo ataque19 dic 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC
qiantu88/CVE-2018-8120
CVE-2018-8120HIGHbajo ataqueransomware19 dic 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Exploit-DBVexDay Proof
IBM Operational Decision Manager 8.x - XML External Entity Injection
CVE-2018-1821HIGHwebappsmultiple19 dic 2018
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) a
46RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-0296HIGHbajo ataque19 dic 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
GitHub PoC
CVE-2007-1567 - WarFTP 1.65 'USER' Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2007-156719 dic 2018
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of s
35RIESGO
abrir
GitHub PoC
Yable/CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware19 dic 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC6
LibSSH Authentication Bypass CVE-2018-10933
CVE-2018-10933CRITICAL19 dic 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
Exploit-DB
Integria IMS 5.0.83 - Cross-Site Request Forgery
CVE-2018-19829webappsphp19 dic 2018
Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary
23RIESGO
abrir
Exploit-DB
Bolt CMS < 3.6.2 - Cross-Site Scripting
CVE-2018-19933webappsphp19 dic 2018
Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and Ne
23RIESGO
abrir
Exploit-DB
Integria IMS 5.0.83 - 'search_string' Cross-Site Scripting
CVE-2018-19828webappsphp19 dic 2018
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
23RIESGO
abrir
GitHub PoC
CVE-2012-5106 - Freefloat FTP Server Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2012-510619 dic 2018
Stack-based buffer overflow in FreeFloat FTP Server 1.0 allows remote authenticated users to execute arbitrary code via
28RIESGO
abrir
GitHub PoC
CVE-2004-2271 - Minishare 1.4.1 HTTP Server Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2004-227119 dic 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RIESGO
abrir
Exploit-DB
Linux Kernel 4.4 - 'rtnetlink' Stack Memory Disclosure
CVE-2016-4486locallinux19 dic 2018
The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain
23RIESGO
abrir
Exploit-DB
Yeswiki Cercopitheque - 'id' SQL Injection
CVE-2018-13045webappsphp19 dic 2018
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to ex
23RIESGO
abrir
GitHub PoC
https://github.com/milo2012/CVE-2018-0296.git
CVE-2018-0296HIGHbajo ataque19 dic 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
Metasploit600
Mailcleaner Remote Code Execution
CVE-2018-2032319 dic 2018
www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitra
30RIESGO
abrir
GitHub PoC
qiantu88/CVE-2017-12617
CVE-2017-12617HIGHbajo ataque19 dic 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC
CVE-2003-0264 - SLMail 5.5 POP3 'PASS' Remote Buffer Overflow Vulnerability. Tested on Windows XP Professional SP3.
CVE-2003-026419 dic 2018
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'jscript!JsArrayFunctionHeapSort' Out-of-Bounds Write
CVE-2018-8631doswindows18 dic 2018
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
35RIESGO
abrir
Exploit-DB
SDL Web Content Manager 8.5.0 - XML External Entity Injection
CVE-2018-19371webappsxml18 dic 2018
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive
23RIESGO
abrir
Exploit-DB
MiniShare 1.4.1 - 'HEAD/POST' Remote Buffer Overflow
CVE-2018-19861remotewindows18 dic 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD re
28RIESGO
abrir
Exploit-DB
MiniShare 1.4.1 - 'HEAD/POST' Remote Buffer Overflow
CVE-2018-19862remotewindows18 dic 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST re
28RIESGO
abrir
GitHub PoC85
An implementation of CVE-2009-0689 for the Nintendo Wii.
CVE-2009-068918 dic 2018
Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation
28RIESGO
abrir
anteriorpágina 860 / 2647siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.