Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
VulnCheck XDB
infoleak
CVE-2018-0296HIGHbajo ataque21 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
GitHub PoC205
Script to test for Cisco ASA path traversal vulnerability (CVE-2018-0296) and extract system information.
CVE-2018-0296HIGHbajo ataque21 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
GitHub PoC107
Test CVE-2018-0296 and extract usernames
CVE-2018-0296HIGHbajo ataque21 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 4.8.1 - (Authenticated) Local File Inclusion (1)
CVE-2018-12613webappsphp21 jun 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add User)
CVE-2018-12602webappsphp21 jun 2018
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
23RIESGO
abrir
Exploit-DB
Dell EMC RecoverPoint < 5.1.2 - Local Root Command Execution
CVE-2018-1235locallinux21 jun 2018
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje
35RIESGO
abrir
Exploit-DB
LFCMS 3.7.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-12603webappsphp21 jun 2018
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authen
23RIESGO
abrir
GitHub PoC
Ektron Content Management System (CMS) 9.20 SP2, remote re-enabling users (CVE-2018–12596)
CVE-2018-1259621 jun 2018
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at
28RIESGO
abrir
Exploit-DB
Redis 5.0 - Denial of Service
CVE-2018-12453doslinux20 jun 2018
Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers t
28RIESGO
abrir
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-12522webappsjava20 jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ pro
23RIESGO
abrir
GitHub PoC1
CVE-2017-5792
CVE-2017-579220 jun 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Desktop Bridge Activation Arbitrary Directory Creation Privilege Escalation
CVE-2018-8208doswindows20 jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Desktop Bridge Virtual Registry CVE-2018-0880 Incomplete Fix Privilege Escalation
CVE-2018-8214doswindows20 jun 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RIESGO
abrir
Exploit-DB
IPConfigure Orchid VMS 2.0.5 - Directory Traversal / Information Disclosure (Metasploit)
CVE-2018-10956webappsmultiple20 jun 2018
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache CouchDB < 2.1.0 - Remote Code Execution
CVE-2017-12636webappslinux20 jun 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RIESGO
abrir
GitHub PoC9
MS15-034 HTTP.sys 远程执行代码检测脚本(MS15-034 HTTP.sys remote execution code poc script)
CVE-2015-1635CRITICALbajo ataque20 jun 2018
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-12523webappsjava20 jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provi
23RIESGO
abrir
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-12524webappsjava20 jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provi
23RIESGO
abrir
Exploit-DB
ntp 4.2.8p11 - Local Buffer Overflow (PoC)
CVE-2018-12327doslinux20 jun 2018
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or es
28RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALbajo ataque20 jun 2018
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
Exploit-DB
MaDDash 2.0.2 - Directory Listing
CVE-2018-12525webappsjava20 jun 2018
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ pr
23RIESGO
abrir
GitHub PoC
malindarathnayake/Intel-CVE-2018-3639-Mitigation_RegistryUpdate
CVE-2018-3639MEDIUM19 jun 2018
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RIESGO
abrir
GitHub PoC1
CVE-2016-2098 simple POC written in bash
CVE-2016-209819 jun 2018
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
Metasploit400
phpMyAdmin Authenticated Remote Code Execution
CVE-2018-1261319 jun 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
Metasploit600
MicroFocus Secure Messaging Gateway Remote Code Execution
CVE-2018-12465CRITICAL19 jun 2018
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RIESGO
abrir
Metasploit600
MicroFocus Secure Messaging Gateway Remote Code Execution
CVE-2018-12464CRITICAL19 jun 2018
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RIESGO
abrir
Metasploit600
Axis Network Camera .srv-to-parhand RCE
CVE-2018-1066118 jun 2018
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RIESGO
abrir
Metasploit600
Axis Network Camera .srv-to-parhand RCE
CVE-2018-1066218 jun 2018
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RIESGO
abrir
Metasploit600
Axis Network Camera .srv-to-parhand RCE
CVE-2018-1066018 jun 2018
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RIESGO
abrir
Exploit-DB
Nikto 2.1.6 - CSV Injection
CVE-2018-11652locallinux18 jun 2018
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S
28RIESGO
abrir
anteriorpágina 895 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.