Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.596exploits catalogados
36.656CVEs con explotación pública
24.695probados en laboratorio
79.526 exploits
Exploit-DBVexDay Proof
XNU - POSIX Shared Memory Mappings have Incorrect Maximum Protection
CVE-2018-4435localmultiple11 dic 2018
A logic issue was addressed with improved restrictions. This issue affected versions prior to iOS 12.1.1, macOS Mojave 1
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-15982HIGHbajo ataqueransomware11 dic 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
Exploit-DBVexDay Proof
McAfee True Key - McAfee.TrueKey.Service Privilege Escalation
CVE-2018-6756HIGHlocalwindows11 dic 2018
True Key (TK) Windows Client - Authentication Abuse vulnerability
41RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-15982HIGHbajo ataqueransomware10 dic 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
GitHub PoC4
个人整理的Centos7.x + Kubernetes-1.12.3 + Dashboard-1.8.3 无 CVE-2018-1002105 漏洞的master节点全自动快速一键安装部署文件,适用于测试环境,生产环境的快速安装部署
CVE-2018-1002105CRITICAL10 dic 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
Exploit-DB
Kubernetes - (Authenticated) Arbitrary Requests
CVE-2018-1002105CRITICALremotemultiple10 dic 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
Exploit-DB
Kubernetes - (Unauthenticated) Arbitrary Requests
CVE-2018-1002105CRITICALremotemultiple10 dic 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
GitHub PoC
Microsoft Equation 3.0/Convert python2 to python3
CVE-2017-11882HIGHbajo ataqueransomware10 dic 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware10 dic 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC1
CVE-2014-0160
CVE-2014-0160HIGHbajo ataque10 dic 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC179
exp of CVE-2018-15982
CVE-2018-15982HIGHbajo ataqueransomware10 dic 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
Metasploit600
ThinkPHP Multiple PHP Injection RCEs
CVE-2019-9082HIGHbajo ataque10 dic 2018
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RIESGO
abrir
Metasploit600
ThinkPHP Multiple PHP Injection RCEs
CVE-2018-20062CRITICALbajo ataque10 dic 2018
An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP
100RIESGO
abrir
Exploit-DB
Adiscon LogAnalyzer < 4.1.7 - Cross-Site Scripting
CVE-2018-19877webappsphp09 dic 2018
login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.
43RIESGO
abrir
Metasploit600
Cisco Prime Infrastructure Runrshell Privilege Escalation
CVE-2018-15439CRITICAL08 dic 2018
Cisco Small Business Switches Privileged Access Vulnerability
55RIESGO
abrir
GitHub PoC2
Proof of consept for CVE-2018-17431
CVE-2018-1743108 dic 2018
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1743108 dic 2018
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir
GitHub PoC223
PoC for CVE-2018-1002105.
CVE-2018-1002105CRITICAL06 dic 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
GitHub PoC13
CVE-2018-15982_PoC
CVE-2018-15982HIGHbajo ataqueransomware06 dic 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
GitHub PoC9
Unrestricted file upload in Adobe ColdFusion
CVE-2018-15961CRITICALbajo ataque06 dic 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-15961CRITICALbajo ataque06 dic 2018
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir
GitHub PoC
Flash sources for CVE-2018-15982 used by NK
CVE-2018-15982HIGHbajo ataqueransomware05 dic 2018
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
GitHub PoC191
Test utility for cve-2018-1002105
CVE-2018-1002105CRITICAL05 dic 2018
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
GitHub PoC
uzzzval/cve-2004-2167
CVE-2004-216705 dic 2018
Multiple buffer overflows in LaTeX2rtf 1.9.15, and possibly other versions, allow remote attackers to execute arbitrary
28RIESGO
abrir
Exploit-DBVexDay Proof
Wireshark - 'find_signature' Heap Out-of-Bounds Read
CVE-2018-19627dosmultiple04 dic 2018
In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/v
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Lync for Mac 2011 - Injection Forced Browsing/Download
CVE-2018-8474doswindows04 dic 2018
A security feature bypass vulnerability exists when Lync for Mac 2011 fails to properly sanitize specially crafted messa
35RIESGO
abrir
GitHub PoC5
dnsmasq rop exploit with NX bypass
CVE-2017-1449304 dic 2018
Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execu
45RIESGO
abrir
Exploit-DB
Rockwell Automation Allen-Bradley PowerMonitor 1000 - Incorrect Access Control Authentication Bypass
CVE-2018-19616webappshardware04 dic 2018
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/rem
28RIESGO
abrir
Exploit-DB
Dolibarr ERP/CRM 8.0.3 - Cross-Site Scripting
CVE-2018-19799webappsphp04 dic 2018
Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.
23RIESGO
abrir
Exploit-DB
FreshRSS 1.11.1 - Cross-Site Scripting
CVE-2018-19782webappsphp04 dic 2018
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject
23RIESGO
abrir
anteriorpágina 865 / 2651siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.