Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.457exploits catalogados
36.589CVEs con explotación pública
24.695probados en laboratorio
79.386 exploits
Exploit-DB
DomainMOD 4.11.01 - Cross-Site Scripting
CVE-2018-19913webappsphp11 dic 2018
DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field.
23RIESGO
abrir
Exploit-DBVexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
CVE-2018-6757HIGHlocalwindows11 dic 2018
True Key (TK) Windows Client - Privilege Escalation vulnerability
41RIESGO
abrir
Exploit-DBVexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
CVE-2018-6755HIGHlocalwindows11 dic 2018
True Key (TK) Windows Client - Weak Directory Permission Vulnerability
41RIESGO
abrir
Exploit-DBVexDay Proof
ZTE ZXHN H168N - Improper Access Restrictions
CVE-2018-7358MEDIUMwebappshardware11 dic 2018
ZTE ZXHN H168N product with versions V2.2.0_PK1.2T5, V2.2.0_PK1.2T2, V2.2.0_PK11T7 and V2.2.0_PK11T have an improper cha
55RIESGO
abrir
Exploit-DB
Kubernetes - (Authenticated) Arbitrary Requests
CVE-2018-1002105CRITICALremotemultiple10 dic 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
Exploit-DB
Kubernetes - (Unauthenticated) Arbitrary Requests
CVE-2018-1002105CRITICALremotemultiple10 dic 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
GitHub PoC4
个人整理的Centos7.x + Kubernetes-1.12.3 + Dashboard-1.8.3 无 CVE-2018-1002105 漏洞的master节点全自动快速一键安装部署文件,适用于测试环境,生产环境的快速安装部署
CVE-2018-1002105CRITICAL10 dic 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
GitHub PoC
Microsoft Equation 3.0/Convert python2 to python3
CVE-2017-11882HIGHbajo ataqueransomware10 dic 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-15982HIGHbajo ataqueransomware10 dic 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
GitHub PoC1
CVE-2014-0160
CVE-2014-0160HIGHbajo ataque10 dic 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware10 dic 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Metasploit600
ThinkPHP Multiple PHP Injection RCEs
CVE-2018-20062CRITICALbajo ataque10 dic 2018
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir
Metasploit600
ThinkPHP Multiple PHP Injection RCEs
CVE-2019-9082HIGHbajo ataque10 dic 2018
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RIESGO
abrir
GitHub PoC179
exp of CVE-2018-15982
CVE-2018-15982HIGHbajo ataqueransomware10 dic 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
Exploit-DB
Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting
CVE-2018-19877webappsphp09 dic 2018
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
43RIESGO
abrir
Metasploit600
Cisco Prime Infrastructure Runrshell Privilege Escalation
CVE-2018-15439CRITICAL08 dic 2018
Cisco Small Business Switches Privileged Access Vulnerability
55RIESGO
abrir
GitHub PoC2
Proof of consept for CVE-2018-17431
CVE-2018-1743108 dic 2018
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1743108 dic 2018
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir
GitHub PoC13
CVE-2018-15982_PoC
CVE-2018-15982HIGHbajo ataqueransomware06 dic 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
GitHub PoC223
PoC for CVE-2018-1002105.
CVE-2018-1002105CRITICAL06 dic 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
GitHub PoC9
Unrestricted file upload in Adobe ColdFusion
CVE-2018-15961CRITICALbajo ataque06 dic 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALbajo ataque06 dic 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir
GitHub PoC
Flash sources for CVE-2018-15982 used by NK
CVE-2018-15982HIGHbajo ataqueransomware05 dic 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
GitHub PoC
uzzzval/cve-2004-2167
CVE-2004-216705 dic 2018
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RIESGO
abrir
GitHub PoC191
Test utility for cve-2018-1002105
CVE-2018-1002105CRITICAL05 dic 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
CVE-2018-8474doswindows04 dic 2018
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa
35RIESGO
abrir
GitHub PoC4
dnsmasq rop exploit with NX bypass
CVE-2017-1449304 dic 2018
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RIESGO
abrir
Exploit-DB
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
CVE-2018-19616webappshardware04 dic 2018
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/rem
28RIESGO
abrir
Exploit-DBVexDay Proof
HP Intelligent Management - Java Deserialization Remote Code Execution (Metasploit)
CVE-2017-12557remotewindows04 dic 2018
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and e
60RIESGO
abrir
Exploit-DB
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection
CVE-2018-15716webappsphp04 dic 2018
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
28RIESGO
abrir
anteriorpágina 862 / 2647siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.