Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC
Just a couple exploits for CVE-2018-11510
CVE-2018-1151018 jun 2018
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir
VulnCheck XDB
local
CVE-2014-4113HIGHbajo ataque18 jun 2018
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Metasploit600
Axis Network Camera .srv-to-parhand RCE
CVE-2018-1066118 jun 2018
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RIESGO
abrir
Metasploit600
Axis Network Camera .srv-to-parhand RCE
CVE-2018-1066218 jun 2018
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RIESGO
abrir
Metasploit600
Axis Network Camera .srv-to-parhand RCE
CVE-2018-1066018 jun 2018
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RIESGO
abrir
Exploit-DB
Nikto 2.1.6 - CSV Injection
CVE-2018-11652locallinux18 jun 2018
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the S
28RIESGO
abrir
VulnCheck XDB
client-side
CVE-2016-3714HIGHbajo ataque18 jun 2018
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-1151018 jun 2018
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque18 jun 2018
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
Pale Moon Browser < 27.9.3 - Use After Free (PoC)
CVE-2018-12292localwindows18 jun 2018
A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
23RIESGO
abrir
GitHub PoC7
Demo-ing CVE-2017-1000253 in a container
CVE-2017-1000253HIGHbajo ataqueransomware18 jun 2018
Linux distributions that have not patched their long-term kernels with https://git.kernel.org/linus/a87938b2e246b81b4fb7
76RIESGO
abrir
Exploit-DB
OEcms 3.1 - Cross-Site Scripting
CVE-2018-12095webappsphp15 jun 2018
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerabil
38RIESGO
abrir
GitHub PoC87
POC for CVE-2018-0824
CVE-2018-0824HIGHbajo ataque15 jun 2018
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-0824HIGHbajo ataque15 jun 2018
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RIESGO
abrir
Exploit-DB
Dimofinf CMS 3.0.0 - Cross-Site Scripting
CVE-2018-12094webappsphp15 jun 2018
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arb
23RIESGO
abrir
Exploit-DB
Joomla! Component Ek Rishta 2.10 - SQL Injection
CVE-2018-12254webappsphp14 jun 2018
router.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to
23RIESGO
abrir
GitHub PoC
MySQL 4.x/5.0 (Linux) - User-Defined Function (UDF) Dynamic Library (2) automation script.
CVE-2012-561314 jun 2018
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RIESGO
abrir
GitHub PoC18
empty_list - exploit for p0 issue 1564 (CVE-2018-4243) iOS 11.0 - 11.3.1 kernel r/w
CVE-2018-424313 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RIESGO
abrir
Exploit-DBVexDay Proof
DHCP Client - Command Injection 'DynoRoot' (Metasploit)
CVE-2018-1111HIGHremotelinux13 jun 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir
Exploit-DB
MACCMS 10 - Cross-Site Request Forgery (Add User)
CVE-2018-12114webappsphp13 jun 2018
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
23RIESGO
abrir
Exploit-DBVexDay Proof
glibc - 'realpath()' Privilege Escalation (Metasploit)
CVE-2018-1000001locallinux13 jun 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Child Process Restriction Mitigation Bypass
CVE-2018-0982localwindows13 jun 2018
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RIESGO
abrir
Exploit-DB
RSLinx Classic and FactoryTalk Linx Gateway - Privilege Escalation
CVE-2018-10619localwindows13 jun 2018
An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.
23RIESGO
abrir
Exploit-DB
Canon PrintMe EFI - Cross-Site Scripting
CVE-2018-12111webappsphp12 jun 2018
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2017-17062webappsxml12 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5754webappsxml12 jun 2018
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5753webappsxml12 jun 2018
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5756webappsxml12 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5751webappsxml12 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5755webappsxml12 jun 2018
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.
23RIESGO
abrir
anteriorpágina 896 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.