Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALbajo ataque04 sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
Exploit-DB
FsPro Labs Event Log Explorer v4.6.1.2115 - XML External Entity Injection
CVE-2018-16252webappswindows03 sep 2018
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RIESGO
abrir
GitHub PoC25
CVE-2017-10366: Oracle PeopleSoft 8.54, 8.55, 8.56 Java deserialization exploit
CVE-2017-1036603 sep 2018
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RIESGO
abrir
GitHub PoC95
Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit
CVE-2017-1000486CRITICALbajo ataque03 sep 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
Exploit-DB
D-Link DIR-615 - Denial of Service (PoC)
CVE-2018-15839doshardware03 sep 2018
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-1000486CRITICALbajo ataque03 sep 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
Exploit-DBVexDay Proof
Network Manager VPNC 1.2.6 - 'Username' Local Privilege Escalation (Metasploit)
CVE-2018-10900HIGHlocallinux31 ago 2018
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac
56RIESGO
abrir
Exploit-DB
DamiCMS 6.0.0 - Cross-Site Request Forgery (Change Admin Password)
CVE-2018-15844webappsphp31 ago 2018
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's pas
23RIESGO
abrir
GitHub PoC13
Mitigate CVE-2018-6389 WordPress load-scripts / load-styles attacks
CVE-2018-638930 ago 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
Exploit-DBVexDay Proof
Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal
CVE-2018-16133webappswindows_x86-6430 ago 2018
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
50RIESGO
abrir
Exploit-DBVexDay Proof
Cybrotech CyBroHttpServer 1.0.3 - Cross-Site Scripting
CVE-2018-16134webappswindows_x86-6430 ago 2018
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
23RIESGO
abrir
Exploit-DB
DLink DIR-601 - Credential Disclosure
CVE-2018-12710webappshardware30 ago 2018
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (whi
45RIESGO
abrir
Metasploit0
Snap Creek Duplicator WordPress plugin code injection
CVE-2018-1720729 ago 2018
An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and
30RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque29 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.7.x - Cross-Site Request Forgery
CVE-2017-1000499webappsphp29 ago 2018
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a
23RIESGO
abrir
GitHub PoC56
This tool takes advantage of CVE-2018-11776 and Shodan to perform mass exploitation of verified and vulnerable Apache Struts servers.
CVE-2018-11776HIGHbajo ataque29 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DBVexDay Proof
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
CVE-2018-15745webappswindows_x8629 ago 2018
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-955428 ago 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
GitHub PoC2
Tiny script to enumerate users using CVE-2017-9554 (forget_passwd.cgi)
CVE-2017-955428 ago 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - JScript RegExp.lastIndex Use-After-Free
CVE-2018-8353doswindows28 ago 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC16
A simple exploit for Apache Struts RCE S2-057 (CVE-2018-11776)
CVE-2018-11776HIGHbajo ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC3
tuxotron/cve-2018-11776-docker
CVE-2018-11776HIGHbajo ataque28 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DB
RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin)
CVE-2018-15884webappshardware27 ago 2018
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RIESGO
abrir
GitHub PoC21
Proof of Concept for CVE-2018-11776
CVE-2018-11776HIGHbajo ataque27 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DBVexDay Proof
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-9948localwindows27 ago 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-11776HIGHbajo ataque27 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DBVexDay Proof
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-9958localwindows27 ago 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir
Exploit-DBVexDay Proof
HP Jetdirect - Path Traversal Arbitrary Code Execution (Metasploit)
CVE-2017-2741remoteunix27 ago 2018
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RIESGO
abrir
anteriorpágina 885 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.