Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
Exploit-DBVexDay Proof
Quest KACE Systems Management - Command Injection (Metasploit)
CVE-2018-11138CRITICALbajo ataqueransomwareremoteunix27 jun 2018
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware26 jun 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
stevenlinfeng/CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque26 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC
Rig Exploit for CVE-2018-8174 As with its previous campaigns, Rig’s Seamless campaign uses malvertising. In this case, the malvertisements have a hidden iframe that redirects victims to Rig’s landing page, which includes an exploit for CVE-2018-8174 and shellcode. This enables remote code execution of the shellcode obfuscated in the landing page. After successful exploitation, a second-stage downloader is retrieved, which appears to be a variant of SmokeLoader due to the URL. It would then download the final payload, a Monero miner.
CVE-2018-8174HIGHbajo ataqueransomware26 jun 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC11
Exploitable target to CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware26 jun 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
PoDoFo 0.9.5 - Buffer Overflow (PoC)
CVE-2018-8002doslinux26 jun 2018
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.
23RIESGO
abrir
Metasploit300
Wordpress Arbitrary File Deletion
CVE-2018-1289526 jun 2018
WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/
30RIESGO
abrir
Exploit-DB
WordPress Plugin iThemes Security < 7.0.3 - SQL Injection
CVE-2018-12636webappsphp25 jun 2018
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admi
28RIESGO
abrir
Metasploit600
PRTG Network Monitor Authenticated RCE
CVE-2018-9276HIGHbajo ataque25 jun 2018
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir
Exploit-DBVexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
CVE-2018-9948remotewindows25 jun 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
Exploit-DB
WordPress Plugin Comments Import & Export < 2.0.4 - CSV Injection
CVE-2018-11526webappsphp25 jun 2018
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
23RIESGO
abrir
GitHub PoC1
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Text Annotations. When setting the point attribute, the process does not properly validate the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process.
CVE-2018-995825 jun 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir
Exploit-DBVexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
CVE-2018-9958remotewindows25 jun 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir
Exploit-DB
DIGISOL DG-BR4000NG - Buffer Overflow (PoC)
CVE-2018-12706doshardware25 jun 2018
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
23RIESGO
abrir
Exploit-DB
WordPress Plugin Advanced Order Export For WooCommerce < 1.5.4 - CSV Injection
CVE-2018-11525webappsphp25 jun 2018
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
23RIESGO
abrir
Exploit-DBVexDay Proof
KVM (Nested Virtualization) - L1 Guest Privilege Escalation
CVE-2018-12904doslinux25 jun 2018
In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause
23RIESGO
abrir
Exploit-DB
DIGISOL DG-BR4000NG - Cross-Site Scripting
CVE-2018-12705webappshardware25 jun 2018
DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
23RIESGO
abrir
GitHub PoC
guwudoor/CVE-2018-8214
CVE-2018-821425 jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-547725 jun 2018
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Exploit-DB
Ecessa ShieldLink SL175EHQ < 10.7.4 - Cross-Site Request Forgery (Add Superuser)
CVE-2018-13032webappshardware25 jun 2018
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogi
23RIESGO
abrir
GitHub PoC520
Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)
CVE-2018-14847CRITICALbajo ataque24 jun 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALbajo ataque24 jun 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC
leandrocamposcardoso/CVE-2017-5638-Mass-Exploit
CVE-2017-5638CRITICALbajo ataqueransomware24 jun 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware24 jun 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (2)
CVE-2018-12613webappsphp22 jun 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
Exploit-DB
QEMU Guest Agent 2.12.50 - Denial of Service
CVE-2018-12617doslinux22 jun 2018
qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 h
28RIESGO
abrir
Exploit-DB
GreenCMS 2.3.0603 - Information Disclosure
CVE-2018-12604webappsphp22 jun 2018
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_d
28RIESGO
abrir
GitHub PoC1
Cisco ASA - CVE-2018-0296 | Exploit
CVE-2018-0296HIGHbajo ataque22 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-0296HIGHbajo ataque22 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-0296HIGHbajo ataque21 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
anteriorpágina 894 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.