Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.526exploits catalogados
36.593CVEs con explotación pública
24.695probados en laboratorio
79.440 exploits
Exploit-DB
xorg-x11-server < 1.20.3 - 'modulepath' Local Privilege Escalation
CVE-2018-14665localmultiple30 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RIESGO
abrir
GitHub PoC50
All about CVE-2018-14667; From what it is to how to successfully exploit it.
CVE-2018-14667CRITICALbajo ataque30 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
Exploit-DBVexDay Proof
VBScript - 'rtFilter' Out-of-Bounds Read
CVE-2018-8552doswindows30 nov 2018
An information disclosure vulnerability exists when VBScript improperly discloses the contents of its memory, which coul
35RIESGO
abrir
Exploit-DB
Schneider Electric PLC - Session Calculation Authentication Bypass
CVE-2017-6026webappshardware30 nov 2018
A Use of Insufficiently Random Values issue was discovered in Schneider Electric Modicon PLCs Modicon M241, firmware ver
35RIESGO
abrir
Exploit-DBVexDay Proof
VBScript - 'OLEAUT32!VariantClear' and 'scrrun!VBADictionary::put_Item' Use-After-Free
CVE-2018-8544doswindows30 nov 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Mac OS X - libxpc MITM Privilege Escalation (Metasploit)
CVE-2018-4237localmacos29 nov 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
50RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JIT - 'ByteCodeParser::handleIntrinsicCall' Type Confusion
CVE-2018-4382dosmultiple29 nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux - Nested User Namespace idmap Limit Local Privilege Escalation (Metasploit)
CVE-2018-18955locallinux29 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
43RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC JIT - 'JSPropertyNameEnumerator' Type Confusion
CVE-2018-4416dosmultiple29 nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
35RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - BytecodeGenerator::hoistSloppyModeFunctionIfNecessary Does not Invalidate the 'ForInContext' Object
CVE-2018-4386dosmultiple29 nov 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RIESGO
abrir
Exploit-DBVexDay Proof
Unitrends Enterprise Backup - bpserverd Privilege Escalation (Metasploit)
CVE-2018-6329locallinux29 nov 2018
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RIESGO
abrir
Exploit-DBVexDay Proof
PHP imap_open - Remote Code Execution (Metasploit)
CVE-2018-19518remotelinux29 nov 2018
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh c
60RIESGO
abrir
GitHub PoC
lol-fi/cve-2011-4862
CVE-2011-486228 nov 2018
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RIESGO
abrir
GitHub PoC1
about CVE-2018-14667 from RichFaces Framework 3.3.4
CVE-2018-14667CRITICALbajo ataque28 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-1920727 nov 2018
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RIESGO
abrir
Exploit-DBVexDay Proof
Netgear Devices - (Unauthenticated) Remote Command Execution (Metasploit)
CVE-2016-1555CRITICALbajo ataqueremotehardware27 nov 2018
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear
100RIESGO
abrir
Exploit-DB
Ticketly 1.0 - 'kind_id' SQL Injection
CVE-2018-18923webappsphp26 nov 2018
AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and
23RIESGO
abrir
GitHub PoC1
The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10
CVE-2018-7690MEDIUM26 nov 2018
MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized Access
33RIESGO
abrir
GitHub PoC1
The SSC REST API contains Insecure Direct Object Reference (IDOR) vulnerabilities in Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10
CVE-2018-7691MEDIUM26 nov 2018
MFSBGN03835 rev.1 - Fortify Software Security Center (SSC), Remote Unauthorized Access
33RIESGO
abrir
Exploit-DBVexDay Proof
Xorg X11 Server - SUID privilege escalation (Metasploit)
CVE-2018-14665localmultiple26 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RIESGO
abrir
GitHub PoC15
RTSPServer Code Execution Vulnerability CVE-2018-4013
CVE-2018-4013CRITICAL24 nov 2018
An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server l
48RIESGO
abrir
GitHub PoC2
zeroto01/CVE-2018-14667
CVE-2018-14667CRITICALbajo ataque23 nov 2018
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
GitHub PoC1
un4ckn0wl3z/CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware22 nov 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware22 nov 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (ldpreload Method)
CVE-2018-18955locallinux21 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
43RIESGO
abrir
GitHub PoC
libSSH bypass
CVE-2018-10933CRITICAL21 nov 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
Exploit-DB
Linux Kernel 4.15.x < 4.19.2 - 'map_write() CAP_SYS_ADMIN' Local Privilege Escalation (cron Method)
CVE-2018-18955locallinux21 nov 2018
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
43RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DfMarshal Unsafe Unmarshaling Privilege Escalation
CVE-2018-8550localwindows20 nov 2018
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerabili
23RIESGO
abrir
GitHub PoC
tafamace/CVE-2016-0793
CVE-2016-079319 nov 2018
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RIESGO
abrir
Exploit-DB
ImageMagick - Memory Leak
CVE-2018-16323localmultiple19 nov 2018
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that ha
35RIESGO
abrir
anteriorpágina 864 / 2648siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.