Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.781exploits catalogados
36.771CVEs con explotación pública
24.695probados en laboratorio
79.697 exploits
GitHub PoC26
lexfo/cve-2017-11176
CVE-2017-1117602 oct 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RIESGO
abrir
GitHub PoC4
MASS Exploiter
CVE-2018-7600CRITICALbajo ataqueransomware02 oct 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALbajo ataque02 oct 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
Exploit-DB
Linux Kernel < 4.11.8 - 'mq_notify: double sock_put()' Local Privilege Escalation
CVE-2017-11176locallinux02 oct 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware02 oct 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
Zahir Enterprise Plus 6 build 10b - Buffer Overflow (SEH)
CVE-2018-17408localwindows_x8601 oct 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RIESGO
abrir
GitHub PoC
likekabin/CVE-2018-17182
CVE-2018-1718201 oct 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir
GitHub PoC1
likekabin/vmacache_CVE-2018-17182
CVE-2018-1718201 oct 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir
Exploit-DB
WUZHICMS 2.0 - Cross-Site Scripting
CVE-2018-17832webappsphp01 oct 2018
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
23RIESGO
abrir
GitHub PoC130
Linux 内核VMA-UAF 提权漏洞(CVE-2018-17182),0day
CVE-2018-1718229 sep 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir
Metasploit300
Zahir Enterprise Plus 6 Stack Buffer Overflow
CVE-2018-1740828 sep 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RIESGO
abrir
Exploit-DBVexDay Proof
PCProtect 4.8.35 - Privilege Escalation
CVE-2018-17776localwindows_x86-6428 sep 2018
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8469remotewindows27 sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8468remotewindows27 sep 2018
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8463remotewindows27 sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RIESGO
abrir
Exploit-DB
Rausoft ID.prove 2.95 - 'Username' SQL injection
CVE-2018-16659webappswindows_x86-6427 sep 2018
An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked q
23RIESGO
abrir
Exploit-DB
EE 4GEE Mini EE40_00_02.00_44 - Privilege Escalation
CVE-2018-14327localwindows27 sep 2018
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before
23RIESGO
abrir
VulnCheck XDB
local
CVE-2014-3153HIGHbajo ataque27 sep 2018
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
GitHub PoC20
Gain root privilege by exploiting CVE-2014-3153 vulnerability
CVE-2014-3153HIGHbajo ataque27 sep 2018
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
GitHub PoC
Make CVE-2007-4607 exploitable again!
CVE-2007-460727 sep 2018
Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used
50RIESGO
abrir
Metasploit600
Navigate CMS Unauthenticated Remote Code Execution
CVE-2018-1755326 sep 2018
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RIESGO
abrir
Metasploit600
Navigate CMS Unauthenticated Remote Code Execution
CVE-2018-1755226 sep 2018
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigat
60RIESGO
abrir
GitHub PoC
bkhablenko/CVE-2017-8046
CVE-2017-804626 sep 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel - VMA Use-After-Free via Buggy vmacache_flush_all() Fastpath Local Privilege Escalation
CVE-2018-17182locallinux26 sep 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir
Exploit-DB
Linux Kernel 2.6.x / 3.10.x / 4.14.x (RedHat / Debian / CentOS) (x64) - 'Mutagen Astronomy' Local Privilege Escalation
CVE-2018-14634HIGHbajo ataquelocallinux_x86-6426 sep 2018
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a
76RIESGO
abrir
GitHub PoC1
cscli/CVE-2017-5223
CVE-2017-522326 sep 2018
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML docume
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-804626 sep 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGTextLayoutAttributes::context' Use-After-Free
CVE-2018-4318dosmultiple25 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DB
Joomla! Component Timetable Schedule 3.6.8 - SQL Injection
CVE-2018-17394webappsphp25 sep 2018
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGTRefElement::updateReferencedText' Use-After-Free
CVE-2018-4315dosmultiple25 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
anteriorpágina 878 / 2657siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.