Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.858exploits catalogados
36.825CVEs con explotación pública
24.695probados en laboratorio
79.697 exploits
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque23 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DB
Geutebrueck re_porter 16 - Cross-Site Scripting
CVE-2018-15533webappshardware22 ago 2018
A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query
23RIESGO
abrir
Exploit-DB
Geutebrueck re_porter 7.8.974.20 - Credential Disclosure
CVE-2018-15534webappshardware22 ago 2018
Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information includin
35RIESGO
abrir
Metasploit600
Apache Struts 2 Namespace Redirect OGNL Injection
CVE-2018-11776HIGHbajo ataque22 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Diagnostics Hub Standard Collector Service Privilege Escalation
CVE-2018-0952localwindows22 ago 2018
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RIESGO
abrir
GitHub PoC3
dangokyo/CVE-2015-5119
CVE-2015-5119HIGHbajo ataque21 ago 2018
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
GitHub PoC111
PoC for Privilege Escalation in Windows 10 Diagnostics Hub Standard Collector Service
CVE-2018-095221 ago 2018
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RIESGO
abrir
Metasploit600
Ghostscript Failed Restore Command Execution
CVE-2018-1650921 ago 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RIESGO
abrir
GitHub PoC534
Exploit written in Python for CVE-2018-15473 with threading and export formats
CVE-2018-15473MEDIUM21 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
a exp for cve-2018-9948/9958 , current shellcode called win-calc
CVE-2018-994821 ago 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSH 2.3 < 7.7 - Username Enumeration
CVE-2018-15473MEDIUMremotelinux21 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Exploit-DBVexDay Proof
Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution
CVE-2018-15576remotephp20 ago 2018
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RIESGO
abrir
Exploit-DB
MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery
CVE-2018-11502webappsphp20 ago 2018
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t
23RIESGO
abrir
Exploit-DB
SEIG Modbus 3.4 - Remote Code Execution
CVE-2013-0662remotewindows_x8620 ago 2018
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RIESGO
abrir
Exploit-DB
WordPress Plugin Tagregator 0.6 - Cross-Site Scripting
CVE-2018-10752webappsphp20 ago 2018
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.
23RIESGO
abrir
Exploit-DB
SEIG Modbus 3.4 - Denial of Service (PoC)
CVE-2013-0662doswindows_x8620 ago 2018
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RIESGO
abrir
Exploit-DB
SEIG SCADA System 9 - Remote Code Execution
CVE-2013-0657remotewindows_x8619 ago 2018
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote
28RIESGO
abrir
GitHub PoC3
CVE-2018-15473 - Opensshenum is an user enumerator exploiting an OpenSsh bug
CVE-2018-15473MEDIUM19 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - InitializeNumberFormat and InitializeDateTimeFormat Type Confusion
CVE-2018-8298HIGHbajo ataquedoswindows17 ago 2018
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
93RIESGO
abrir
Exploit-DB
ADM 3.1.2RHG1 - Remote Code Execution
CVE-2018-11510webappshardware17 ago 2018
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - ImplicitCallFlags Check Bypass with Intl
CVE-2018-8288doswindows17 ago 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'DictionaryPropertyDescriptor::CopyFrom' Type Confusion
CVE-2018-8291doswindows17 ago 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Parameter Scope Parsing Type Confusion
CVE-2018-8279doswindows17 ago 2018
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
45RIESGO
abrir
GitHub PoC159
OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).
CVE-2018-15473MEDIUM17 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Exploit-DB
WebkitGTK+ 2.20.3 - 'ImageBufferCairo::getImageData()' Buffer Overflow (PoC)
CVE-2018-12293locallinux16 ago 2018
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKi
28RIESGO
abrir
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-14059webappsphp16 ago 2018
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick,
23RIESGO
abrir
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-14058webappsphp16 ago 2018
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8120HIGHbajo ataqueransomware16 ago 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC1
CVE-2018-8120 Windows LPE exploit
CVE-2018-8120HIGHbajo ataqueransomware16 ago 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-15140webappslinux16 ago 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir
anteriorpágina 884 / 2657siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.