Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
Exploit-DB
Oracle WebLogic 12.1.2.0 - RMI Registry UnicastRef Object Java Deserialization Remote Code Execution
CVE-2017-3248webappsmultiple07 jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir
Exploit-DB
Airties AIR5444TT - Cross-Site Scripting
CVE-2018-8738webappswindows06 jul 2018
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
23RIESGO
abrir
Exploit-DB
PolarisOffice 2017 8 - Remote Code Execution
CVE-2018-12589remotewindows06 jul 2018
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in
28RIESGO
abrir
GitHub PoC1
lonehand/Oracle-WebLogic-CVE-2017-10271-master
CVE-2017-10271HIGHbajo ataqueransomware06 jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
ADB Broadband Gateways / Routers - Privilege Escalation
CVE-2018-13110localhardware05 jul 2018
All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerabilit
23RIESGO
abrir
Exploit-DB
ADB Broadband Gateways / Routers - Local Root Jailbreak
CVE-2018-13108localhardware05 jul 2018
All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerabilit
23RIESGO
abrir
Exploit-DB
ADB Broadband Gateways / Routers - Authorization Bypass
CVE-2018-13109webappshardware05 jul 2018
All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerabili
35RIESGO
abrir
Exploit-DB
ShopNx - Arbitrary File Upload
CVE-2018-12519webappsphp04 jul 2018
An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious
23RIESGO
abrir
Exploit-DB
Online Trade - Information Disclosure
CVE-2018-12908webappsphp04 jul 2018
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RIESGO
abrir
Exploit-DBVexDay Proof
CMS Made Simple 2.2.5 - (Authenticated) Remote Code Execution
CVE-2018-1000094webappsphp04 jul 2018
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows a
50RIESGO
abrir
Metasploit600
CMS Made Simple Authenticated RCE via File Upload/Copy
CVE-2018-100009403 jul 2018
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows a
50RIESGO
abrir
Exploit-DB
OpenSLP 2.0.0 - Double-Free
CVE-2018-12938doslinux03 jul 2018
20RIESGO
abrir
Exploit-DBVexDay Proof
Boxoft WAV to MP3 Converter 1.1 - Buffer Overflow (Metasploit)
CVE-2015-7243localwindows03 jul 2018
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RIESGO
abrir
Exploit-DB
ntop-ng < 3.4.180617 - Authentication Bypass
CVE-2018-12520webappslua03 jul 2018
An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seede
28RIESGO
abrir
Exploit-DB
Delta Industrial Automation COMMGR 1.08 - Stack Buffer Overflow (PoC)
CVE-2018-10594doshardware02 jul 2018
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPS
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8736remotelinux02 jul 2018
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RIESGO
abrir
Metasploit300
Delta Electronics Delta Industrial Automation COMMGR 1.08 Stack Buffer Overflow
CVE-2018-1059402 jul 2018
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPS
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8735remotelinux02 jul 2018
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RIESGO
abrir
Exploit-DBVexDay Proof
FTPShell Client 6.70 (Enterprise Edition) - Stack Buffer Overflow (Metasploit)
CVE-2018-7573remotewindows02 jul 2018
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RIESGO
abrir
GitHub PoC3
likekabin/CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque02 jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
Exploit-DBVexDay Proof
VMware NSX SD-WAN Edge < 3.1.2 - Command Injection
CVE-2018-6961HIGHbajo ataquewebappshardware02 jul 2018
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8734remotelinux02 jul 2018
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8733remotelinux02 jul 2018
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-999530 jun 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC
Aruthw/CVE-2014-6271
CVE-2014-6271CRITICALbajo ataque30 jun 2018
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DBVexDay Proof
HongCMS 3.0.0 - (Authenticated) SQL Injection
CVE-2018-12912webappsphp28 jun 2018
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via a
23RIESGO
abrir
GitHub PoC
qy1202/https-github.com-Ridter-CVE-2017-11882-
CVE-2017-11882HIGHbajo ataqueransomware28 jun 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DB
Cisco Adaptive Security Appliance - Path Traversal
CVE-2018-0296HIGHbajo ataquewebappshardware28 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
Exploit-DB
BEESCMS 4.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-12739webappsphp28 jun 2018
In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
23RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-363628 jun 2018
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir
anteriorpágina 893 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.