Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
Metasploit600
Apache Struts 2 Namespace Redirect OGNL Injection
CVE-2018-11776HIGHbajo ataque22 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Metasploit600
Ghostscript Failed Restore Command Execution
CVE-2018-1650921 ago 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RIESGO
abrir
GitHub PoC3
dangokyo/CVE-2015-5119
CVE-2015-5119HIGHbajo ataque21 ago 2018
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSH 2.3 < 7.7 - Username Enumeration
CVE-2018-15473MEDIUMremotelinux21 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC
a exp for cve-2018-9948/9958 , current shellcode called win-calc
CVE-2018-994821 ago 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
GitHub PoC534
Exploit written in Python for CVE-2018-15473 with threading and export formats
CVE-2018-15473MEDIUM21 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC111
PoC for Privilege Escalation in Windows 10 Diagnostics Hub Standard Collector Service
CVE-2018-095221 ago 2018
An Elevation of Privilege vulnerability exists when Diagnostics Hub Standard Collector allows file creation in arbitrary
23RIESGO
abrir
Exploit-DB
SEIG Modbus 3.4 - Denial of Service (PoC)
CVE-2013-0662doswindows_x8620 ago 2018
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RIESGO
abrir
Exploit-DBVexDay Proof
Easylogin Pro 1.3.0 - 'Encryptor.php' Unserialize Remote Code Execution
CVE-2018-15576remotephp20 ago 2018
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited
23RIESGO
abrir
Exploit-DB
MyBB Moderator Log Notes Plugin 1.1 - Cross-Site Request Forgery
CVE-2018-11502webappsphp20 ago 2018
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display t
23RIESGO
abrir
Exploit-DB
SEIG Modbus 3.4 - Remote Code Execution
CVE-2013-0662remotewindows_x8620 ago 2018
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow
28RIESGO
abrir
Exploit-DB
WordPress Plugin Tagregator 0.6 - Cross-Site Scripting
CVE-2018-10752webappsphp20 ago 2018
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.
23RIESGO
abrir
Exploit-DB
SEIG SCADA System 9 - Remote Code Execution
CVE-2013-0657remotewindows_x8619 ago 2018
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote
28RIESGO
abrir
GitHub PoC3
CVE-2018-15473 - Opensshenum is an user enumerator exploiting an OpenSsh bug
CVE-2018-15473MEDIUM19 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Exploit-DB
ADM 3.1.2RHG1 - Remote Code Execution
CVE-2018-11510webappshardware17 ago 2018
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - InitializeNumberFormat and InitializeDateTimeFormat Type Confusion
CVE-2018-8298HIGHbajo ataquedoswindows17 ago 2018
A remote code execution vulnerability exists in the way that the ChakraCore scripting engine handles objects in memory,
93RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - ImplicitCallFlags Check Bypass with Intl
CVE-2018-8288doswindows17 ago 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'DictionaryPropertyDescriptor::CopyFrom' Type Confusion
CVE-2018-8291doswindows17 ago 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir
GitHub PoC159
OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).
CVE-2018-15473MEDIUM17 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Parameter Scope Parsing Type Confusion
CVE-2018-8279doswindows17 ago 2018
A remote code execution vulnerability exists when Microsoft Edge improperly accesses objects in memory, aka "Microsoft E
45RIESGO
abrir
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-14059webappsphp16 ago 2018
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick,
23RIESGO
abrir
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-14058webappsphp16 ago 2018
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RIESGO
abrir
Exploit-DB
WebkitGTK+ 2.20.3 - 'ImageBufferCairo::getImageData()' Buffer Overflow (PoC)
CVE-2018-12293locallinux16 ago 2018
The getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKi
28RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8120HIGHbajo ataqueransomware16 ago 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-15141webappslinux16 ago 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir
Exploit-DBVexDay Proof
OpenSSH 2.3 < 7.7 - Username Enumeration (PoC)
CVE-2018-15473MEDIUMremotelinux16 ago 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Exploit-DBVexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-15142webappslinux16 ago 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir
Exploit-DBVexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-15140webappslinux16 ago 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir
GitHub PoC1
CVE-2018-8120 Windows LPE exploit
CVE-2018-8120HIGHbajo ataqueransomware16 ago 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Exploit-DB
Pimcore 5.2.3 - SQL Injection / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-14057webappsphp16 ago 2018
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati
23RIESGO
abrir
anteriorpágina 887 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.