Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.858exploits catalogados
36.825CVEs con explotación pública
24.695probados en laboratorio
79.697 exploits
Metasploit300
Microsoft Windows ALPC Task Scheduler Local Privilege Elevation
CVE-2018-8440HIGHbajo ataqueransomware27 ago 2018
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
91RIESGO
abrir
Exploit-DBVexDay Proof
HP Jetdirect - Path Traversal Arbitrary Code Execution (Metasploit)
CVE-2017-2741remoteunix27 ago 2018
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RIESGO
abrir
Exploit-DB
Gleez CMS 1.2.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-15845webappsphp27 ago 2018
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Plainview Activity Monitor 20161228 - (Authenticated) Command Injection
CVE-2018-15877webappsphp27 ago 2018
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RIESGO
abrir
Exploit-DBVexDay Proof
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-9948localwindows27 ago 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
Exploit-DBVexDay Proof
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-9958localwindows27 ago 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque27 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DBVexDay Proof
Electron WebPreferences - Remote Code Execution
CVE-2018-15685remotemultiple27 ago 2018
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindow
28RIESGO
abrir
GitHub PoC21
Proof of Concept for CVE-2018-11776
CVE-2018-11776HIGHbajo ataque27 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DB
RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin)
CVE-2018-15884webappshardware27 ago 2018
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Responsive FileManager < 9.13.4 - Directory Traversal
CVE-2018-15536webappsphp27 ago 2018
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc
23RIESGO
abrir
Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1)
CVE-2018-11776HIGHbajo ataqueremotelinux26 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DB
ManageEngine ADManager Plus 6.5.7 - Cross-Site Scripting
CVE-2018-15740webappswindows_x86-6426 ago 2018
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
23RIESGO
abrir
Metasploit600
Wordpress Plainview Activity Monitor RCE
CVE-2018-1587726 ago 2018
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DB
ManageEngine ADManager Plus 6.5.7 - HTML Injection
CVE-2018-15608webappswindows25 ago 2018
Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
23RIESGO
abrir
GitHub PoC3
moayadalmalat/CVE-2017-12636
CVE-2017-1263625 ago 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RIESGO
abrir
GitHub PoC303
An exploit for Apache Struts CVE-2018-11776
CVE-2018-11776HIGHbajo ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC4
Environment for CVE-2018-11776 / S2-057 (Apache Struts 2)
CVE-2018-11776HIGHbajo ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC12
Vulnerable docker container for CVE-2018-11776
CVE-2018-11776HIGHbajo ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (2)
CVE-2018-11776HIGHbajo ataqueremotemultiple25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC10
CVE-2018-11776(S2-057) EXPLOIT CODE
CVE-2018-11776HIGHbajo ataque24 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque24 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC123
Working Python test and PoC for CVE-2018-11776, includes Docker lab
CVE-2018-11776HIGHbajo ataque24 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-8414HIGHbajo ataque24 ago 2018
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque24 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC21
Simple poc of CVE-2018-8414 Windows Package Setting RCE Vulnerability
CVE-2018-8414HIGHbajo ataque24 ago 2018
A remote code execution vulnerability exists when the Windows Shell does not properly validate file paths, aka "Windows
93RIESGO
abrir
GitHub PoC15
Creating a vulnerable environment and the PoC
CVE-2018-11776HIGHbajo ataque23 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
anteriorpágina 883 / 2657siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.