Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.858exploits catalogados
36.825CVEs con explotación pública
24.695probados en laboratorio
79.697 exploits
Exploit-DB
Cisco Umbrella Roaming Client 2.0.168 - Local Privilege Escalation
CVE-2018-0438localwindows_x86-6406 sep 2018
Cisco Umbrella Enterprise Roaming Client Privilege Escalation Vulnerability
23RIESGO
abrir
Exploit-DB
Tenda ADSL Router D152 - Cross-Site Scripting
CVE-2018-14497webappshardware05 sep 2018
Tenda D152 ADSL routers allow XSS via a crafted SSID.
23RIESGO
abrir
GitHub PoC2
Apache Struts version analyzer (Ansible) based on CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware04 sep 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC5
A remote code execution exploit for WebLogic based on CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque04 sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALbajo ataque04 sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALbajo ataque03 sep 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
GitHub PoC95
Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit
CVE-2017-1000486CRITICALbajo ataque03 sep 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
GitHub PoC25
CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit
CVE-2017-1036603 sep 2018
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RIESGO
abrir
Exploit-DB
D-Link DIR-615 - Denial of Service (PoC)
CVE-2018-15839doshardware03 sep 2018
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
35RIESGO
abrir
Exploit-DB
FsPro Labs Event Log Explorer v4.6.1.2115 - XML External Entity Injection
CVE-2018-16252webappswindows03 sep 2018
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RIESGO
abrir
Exploit-DB
DamiCMS 6.0.0 - Cross-Site Request Forgery (Change Admin Password)
CVE-2018-15844webappsphp31 ago 2018
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's pas
23RIESGO
abrir
Exploit-DBVexDay Proof
Network Manager VPNC 1.2.6 - 'Username' Local Privilege Escalation (Metasploit)
CVE-2018-10900HIGHlocallinux31 ago 2018
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac
56RIESGO
abrir
GitHub PoC13
Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks
CVE-2018-638930 ago 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
Exploit-DB
DLink DIR-601 - Credential Disclosure
CVE-2018-12710webappshardware30 ago 2018
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (whi
45RIESGO
abrir
Exploit-DBVexDay Proof
Cybrotech CyBroHttpServer 1.0.3 - Cross-Site Scripting
CVE-2018-16134webappswindows_x86-6430 ago 2018
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
23RIESGO
abrir
Exploit-DBVexDay Proof
Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal
CVE-2018-16133webappswindows_x86-6430 ago 2018
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
50RIESGO
abrir
Exploit-DBVexDay Proof
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
CVE-2018-15745webappswindows_x8629 ago 2018
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.7.x - Cross-Site Request Forgery
CVE-2017-1000499webappsphp29 ago 2018
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a
23RIESGO
abrir
GitHub PoC56
This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers.
CVE-2018-11776HIGHbajo ataque29 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Metasploit0
Snap Creek Duplicator WordPress plugin code injection
CVE-2018-1720729 ago 2018
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and
30RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque29 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC3
tuxotron/cve-2018-11776-docker
CVE-2018-11776HIGHbajo ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC16
A simple exploit for Apache Struts RCE S2-057 (CVE-2018-11776)
CVE-2018-11776HIGHbajo ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC2
Tiny script to enumerate users using CVE-2017-9554 (forget_passwd.cgi)
CVE-2017-955428 ago 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - JScript RegExp.lastIndex Use-After-Free
CVE-2018-8353doswindows28 ago 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-955428 ago 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
Exploit-DBVexDay Proof
Responsive FileManager < 9.13.4 - Directory Traversal
CVE-2018-15536webappsphp27 ago 2018
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc
23RIESGO
abrir
Exploit-DB
Gleez CMS 1.2.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-15845webappsphp27 ago 2018
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
23RIESGO
abrir
anteriorpágina 882 / 2657siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.