Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-5753webappsxml12 jun 2018
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev
23RIESGO
abrir
Exploit-DB
Canon PrintMe EFI - Cross-Site Scripting
CVE-2018-12111webappsphp12 jun 2018
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DB
WebKitGTK+ < 2.21.3 - 'WebKitFaviconDatabase' Denial of Service (Metasploit)
CVE-2018-11646doslinux11 jun 2018
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RIESGO
abrir
Exploit-DB
Schools Alert Management Script - SQL Injection
CVE-2018-12055webappsphp11 jun 2018
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph
23RIESGO
abrir
Exploit-DB
Schools Alert Management Script - Arbitrary File Deletion
CVE-2018-12053webappsphp11 jun 2018
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p
28RIESGO
abrir
Exploit-DB
WordPress Plugin Pie Register < 3.0.9 - Blind SQL Injection
CVE-2018-10969webappsphp11 jun 2018
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DB
Schools Alert Management Script - 'get_sec.php' SQL Injection
CVE-2018-12052webappsphp11 jun 2018
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
23RIESGO
abrir
Exploit-DB
Schools Alert Management Script - Arbitrary File Read
CVE-2018-12054webappsphp11 jun 2018
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol
50RIESGO
abrir
VulnCheck XDB
local
CVE-2016-7255HIGHbajo ataqueransomware09 jun 2018
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
GitHub PoC11
A demonstration of how page tables can be used to run arbitrary code in ring-0 and lead to a privesc. Uses CVE-2016-7255 as an example.
CVE-2016-7255HIGHbajo ataqueransomware09 jun 2018
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
Metasploit300
Splunk __raw Server Info Disclosure
CVE-2018-1140908 jun 2018
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
60RIESGO
abrir
Exploit-DB
Splunk < 7.0.1 - Information Disclosure
CVE-2018-11409webappslinux08 jun 2018
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
60RIESGO
abrir
Exploit-DB
XiongMai uc-httpd 1.0.0 - Buffer Overflow
CVE-2018-10088webappshardware08 jun 2018
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
50RIESGO
abrir
GitHub PoC
teawater/CVE-2017-5123
CVE-2017-512308 jun 2018
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome - Integer Overflow when Processing WebAssembly Locals
CVE-2018-6092dosmultiple08 jun 2018
An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker t
23RIESGO
abrir
Exploit-DBVexDay Proof
WebRTC - VP9 Frame Processing Out-of-Bounds Memory Access
CVE-2018-6130dosmultiple08 jun 2018
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to pot
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - WebAssembly Compilation Info Leak
CVE-2018-4222dosmultiple08 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - Use-After-Free when Resuming Generator
CVE-2018-4218dosmultiple08 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
23RIESGO
abrir
Exploit-DBVexDay Proof
WebRTC - VP9 Missing Frame Processing Out-of-Bounds Memory Access
CVE-2018-6129dosmultiple08 jun 2018
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially per
23RIESGO
abrir
Exploit-DBVexDay Proof
TrendMicro OfficeScan XG 11.0 - Change Prevention Bypass
CVE-2018-10507localwindows08 jun 2018
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or
23RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8120HIGHbajo ataqueransomware07 jun 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC293
CVE-2018-8120 Exploit for Win2003 Win2008 WinXP Win7
CVE-2018-8120HIGHbajo ataqueransomware07 jun 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Exploit-DB
Monstra CMS < 3.0.4 - Cross-Site Scripting (1)
CVE-2018-10118webappsphp07 jun 2018
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RIESGO
abrir
Exploit-DBVexDay Proof
XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
CVE-2018-4241dosmultiple06 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RIESGO
abrir
GitHub PoC4
CVE-2018-4241: XNU kernel heap overflow due to bad bounds checking in MPTCP for iOS 11 - 11.3.1released by Ian Beer
CVE-2018-424106 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RIESGO
abrir
Metasploit300
Cisco ASA Directory Traversal
CVE-2018-0296HIGHbajo ataque06 jun 2018
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-10562CRITICALbajo ataqueransomware06 jun 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
Exploit-DBVexDay Proof
PHP 7.2.2 - 'php_stream_url_wrap_http_ex' Buffer Overflow
CVE-2018-7584dosphp06 jun 2018
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer
45RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware06 jun 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS Kernel - Heap Overflow Due to Lack of Lower Size Check in getvolattrlist
CVE-2018-4243dosmultiple06 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RIESGO
abrir
anteriorpágina 897 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.