Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC4
CVE-2018-4241: XNU kernel heap overflow due to bad bounds checking in MPTCP for iOS 11 - 11.3.1released by Ian Beer
CVE-2018-424106 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RIESGO
abrir
Exploit-DBVexDay Proof
XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
CVE-2018-4241dosmultiple06 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RIESGO
abrir
GitHub PoC3
Exploit for CVE-2018-10562
CVE-2018-10562CRITICALbajo ataqueransomware06 jun 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-8581HIGHbajo ataqueransomware06 jun 2018
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4656HIGHbajo ataqueremoteios05 jun 2018
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4655MEDIUMbajo ataqueremoteios05 jun 2018
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir
Exploit-DBVexDay Proof
MyBB Recent Threads Plugin 1.0 - Cross-Site Scripting
CVE-2018-11715webappsphp05 jun 2018
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
23RIESGO
abrir
Exploit-DB
WebKitGTK+ < 2.21.3 - Crash (PoC)
CVE-2018-11646locallinux05 jun 2018
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RIESGO
abrir
Exploit-DB
Pagekit < 1.0.13 - Cross-Site Scripting Code Generator
CVE-2018-11564webappsphp05 jun 2018
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RIESGO
abrir
Exploit-DB
Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email)
CVE-2018-8718webappslinux05 jun 2018
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALbajo ataque05 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC107
Weblogic 反序列化漏洞(CVE-2018-2628)
CVE-2018-2628CRITICALbajo ataque05 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
Exploit-DB
Linux Kernel < 4.16.11 - 'ext4_read_inline_data()' Memory Corruption
CVE-2018-11412doslinux05 jun 2018
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untruste
28RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4657HIGHbajo ataqueremoteios05 jun 2018
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware05 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC
cve-2018-2628 反弹shell
CVE-2018-2628CRITICALbajo ataque05 jun 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC5
ne1llee/cve-2018-8120
CVE-2018-8120HIGHbajo ataqueransomware05 jun 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Exploit-DB
CyberArk < 10 - Memory Disclosure
CVE-2018-9842remotelinux04 jun 2018
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RIESGO
abrir
Exploit-DB
Zip-n-Go 4.9 - Buffer Overflow (SEH)
CVE-2018-16302localwindows04 jun 2018
MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
23RIESGO
abrir
Exploit-DB
EMS Master Calendar < 8.0.0.20180520 - Cross-Site Scripting
CVE-2018-11628webappsaspx04 jun 2018
Data input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malici
23RIESGO
abrir
Exploit-DB
Brother HL Series Printers 1.15 - Cross-Site Scripting
CVE-2018-11581webappshardware04 jun 2018
Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DB
SearchBlox 8.6.7 - XML External Entity Injection
CVE-2018-11586webappsjava04 jun 2018
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to re
28RIESGO
abrir
Exploit-DB
GreenCMS 2.3.0603 - Cross-Site Request Forgery (Add Admin)
CVE-2018-11671webappsphp03 jun 2018
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php
23RIESGO
abrir
Metasploit300
WebKitGTK+ WebKitFaviconDatabase DoS
CVE-2018-1164603 jun 2018
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RIESGO
abrir
Exploit-DB
GreenCMS 2.3.0603 - Cross-Site Request Forgery / Remote Code Execution
CVE-2018-11670webappsphp03 jun 2018
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary
23RIESGO
abrir
GitHub PoC6
MS Word MS WordPad via IE VBS Engine RCE
CVE-2018-8174HIGHbajo ataqueransomware01 jun 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-8174HIGHbajo ataqueransomware01 jun 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC
My version - CloudMe-Sync-1.10.9---Buffer-Overflow-SEH-DEP-Bypass on Win7 x64 CVE-2018-6892
CVE-2018-689231 may 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - EntrySimpleObjectSlotGetter Type Confusion
CVE-2018-8133doswindows31 may 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
GitHub PoC
My version - [Win10 x64] CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass CVE-2018-6892
CVE-2018-689231 may 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
anteriorpágina 898 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.