Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.466exploits catalogados
36.589CVEs con explotación pública
24.695probados en laboratorio
79.386 exploits
Exploit-DBVexDay Proof
HP Intelligent Management - Java Deserialization Remote Code Execution (Metasploit)
CVE-2017-12557remotewindows04 dic 2018
A Remote Code Execution vulnerability in HPE intelligent Management Center (iMC) PLAT version IMC Plat 7.3 E0504P2 and e
60RIESGO
abrir
Exploit-DB
DomainMOD 4.11.01 - Custom Domain Fields Cross-Site Scripting
CVE-2018-19750webappsphp04 dic 2018
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma
23RIESGO
abrir
Exploit-DB
DomainMOD 4.11.01 - Registrar Cross-Site Scripting
CVE-2018-19752webappsphp04 dic 2018
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
38RIESGO
abrir
Exploit-DB
FreshRSS 1.11.1 - Cross-Site Scripting
CVE-2018-19782webappsphp04 dic 2018
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RIESGO
abrir
GitHub PoC
CVE-2014-8682
CVE-2014-868204 dic 2018
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow r
50RIESGO
abrir
Exploit-DB
Xorg X11 Server (AIX) - Local Privilege Escalation
CVE-2018-14665localaix04 dic 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RIESGO
abrir
Exploit-DB
NEC Univerge Sv9100 WebPro - 6.00 - Predictable Session ID / Clear Text Password Storage
CVE-2018-11742webappshardware04 dic 2018
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RIESGO
abrir
Exploit-DB
OpenSSH < 7.7 - User Enumeration (2)
CVE-2018-15473MEDIUMremotelinux04 dic 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Exploit-DB
DomainMOD 4.11.01 - Custom SSL Fields Cross-Site Scripting
CVE-2018-19751webappsphp04 dic 2018
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
38RIESGO
abrir
Exploit-DB
NUUO NVRMini2 3.9.1 - (Authenticated) Command Injection
CVE-2018-15716webappsphp04 dic 2018
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
28RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - 'find_signature' Heap Out-of-Bounds Read
CVE-2018-19627dosmultiple04 dic 2018
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/v
28RIESGO
abrir
Exploit-DB
DomainMOD 4.11.01 - Owner name Field Cross-Site Scripting
CVE-2018-19749webappsphp04 dic 2018
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
38RIESGO
abrir
GitHub PoC
CVE-2014-4511
CVE-2014-451103 dic 2018
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in
60RIESGO
abrir
GitHub PoC
This is an exploitation guide for CVE-2016-2233
CVE-2016-223303 dic 2018
Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC serve
28RIESGO
abrir
Exploit-DB
CyberArk 9.7 - Memory Disclosure
CVE-2018-9842remotewindows03 dic 2018
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RIESGO
abrir
GitHub PoC
A VENOM (CVE-2015-3456) Exploit / PoC written in C.
CVE-2015-345603 dic 2018
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a
28RIESGO
abrir
Exploit-DB
Apache Superset < 0.23 - Remote Code Execution
CVE-2018-8021webappslinux03 dic 2018
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RIESGO
abrir
GitHub PoC1
A collection of code pertaining to CVE-2016-0728 (various authors)
CVE-2016-072803 dic 2018
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2016-072803 dic 2018
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RIESGO
abrir
GitHub PoC
CVE-2016-1240 exploit and patch
CVE-2016-124002 dic 2018
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RIESGO
abrir
GitHub PoC104
CVE-2018-8021 Proof-Of-Concept and Exploit
CVE-2018-802102 dic 2018
Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to pos
35RIESGO
abrir
GitHub PoC39
PrestaShop (1.6.x <= 1.6.1.23 or 1.7.x <= 1.7.4.4) Back Office Remote Code Execution (CVE-2018-19126)
CVE-2018-1912601 dic 2018
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file u
28RIESGO
abrir
Exploit-DB
xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
CVE-2018-14665localmultiple30 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RIESGO
abrir
Exploit-DBVexDay Proof
VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
CVE-2018-8544doswindows30 nov 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
VBScript - 'rtFilter' Out-of-Bounds Read
CVE-2018-8552doswindows30 nov 2018
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which coul
35RIESGO
abrir
Exploit-DB
Schneider Electric PLC - Session Calculation Authentication Bypass
CVE-2017-6026webappshardware30 nov 2018
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware ver
35RIESGO
abrir
GitHub PoC50
All about CVE-2018-14667; From what it is to how to successfully exploit it.
CVE-2018-14667CRITICALbajo ataque30 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
Exploit-DB
PhpSpreadsheet < 1.5.0 - XML External Entity (XXE)
CVE-2018-19277webappsphp30 nov 2018
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 enco
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-14667CRITICALbajo ataque30 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC JIT - 'JSPropertyNameEnumerator' Type Confusion
CVE-2018-4416dosmultiple29 nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RIESGO
abrir
anteriorpágina 863 / 2647siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.