Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
GitHub PoC
My version - [Win10 x64] CloudMe-Sync-1.10.9-Buffer-Overflow-SEH-DEP-Bypass CVE-2018-6892
CVE-2018-689231 may 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
Metasploit600
Quest KACE Systems Management Command Injection
CVE-2018-11138CRITICALbajo ataqueransomware31 may 2018
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by
100RIESGO
abrir
Exploit-DB
Siemens SIMATIC S7-300 CPU - Remote Denial of Service
CVE-2015-2177HIGHdoslinux30 may 2018
Siemens SIMATIC S7-300 CPU devices allow remote attackers to cause a denial of service (defect-mode transition) via craf
53RIESGO
abrir
Metasploit300
Dolibarr Gather Credentials via SQL Injection
CVE-2018-1009430 may 2018
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vecto
60RIESGO
abrir
Exploit-DBVexDay Proof
Dolibarr ERP/CRM 7.0.0 - (Authenticated) SQL Injection
CVE-2018-10094webappsphp30 may 2018
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vecto
60RIESGO
abrir
Exploit-DBVexDay Proof
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
CVE-2018-6409webappsphp30 may 2018
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path fr
28RIESGO
abrir
Exploit-DBVexDay Proof
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
CVE-2018-6410webappsphp30 may 2018
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-8174HIGHbajo ataqueransomware30 may 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1123LOWlocallinux30 may 2018
procps-ng before version 3.3.15 is vulnerable to a denial of service in ps via mmap buffer overflow. Inbuilt protection
28RIESGO
abrir
Exploit-DB
SearchBlox 8.6.6 - Cross-Site Request Forgery
CVE-2018-11538webappsjava30 may 2018
servlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST param
28RIESGO
abrir
Exploit-DBVexDay Proof
MachForm < 4.2.3 - SQL Injection / Path Traversal / Upload Bypass
CVE-2018-6411webappsphp30 may 2018
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically
23RIESGO
abrir
Exploit-DB
Yosoro 1.0.4 - Remote Code Execution
CVE-2018-11522webappsmacos30 may 2018
Yosoro 1.0.4 has stored XSS.
23RIESGO
abrir
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1122HIGHlocallinux30 may 2018
procps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset
41RIESGO
abrir
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1124HIGHlocallinux30 may 2018
procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec
41RIESGO
abrir
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1120LOWlocallinux30 may 2018
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory
28RIESGO
abrir
Exploit-DB
Procps-ng - Multiple Vulnerabilities
CVE-2018-1121LOWlocallinux30 may 2018
procps-ng, procps is vulnerable to a process hiding through race condition. Since the kernel's proc_pid_readdir() return
28RIESGO
abrir
GitHub PoC139
CVE-2018-8174_python
CVE-2018-8174HIGHbajo ataqueransomware30 may 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo - Arbitrary File Upload
CVE-2018-11523webappshardware29 may 2018
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
23RIESGO
abrir
Exploit-DB
MyBB ChangUonDyU Plugin 1.0.2 - Cross-Site Scripting
CVE-2018-11532webappsphp29 may 2018
An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonst
23RIESGO
abrir
Exploit-DB
Sitemakin SLAC 1.0 - 'my_item_search' SQL Injection
CVE-2018-11535webappsphp29 may 2018
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.
23RIESGO
abrir
Exploit-DB
wityCMS 0.6.1 - Cross-Site Scripting
CVE-2018-11512webappsphp28 may 2018
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "Ge
23RIESGO
abrir
Exploit-DB
DomainMod 4.09.03 - 'sslpaid' Cross-Site Scripting
CVE-2018-11404webappsphp28 may 2018
DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
23RIESGO
abrir
Exploit-DB
DomainMod 4.09.03 - 'oid' Cross-Site Scripting
CVE-2018-11403webappsphp28 may 2018
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
23RIESGO
abrir
Metasploit600
IBM QRadar SIEM Unauthenticated Remote Code Execution
CVE-2018-1612MEDIUM28 may 2018
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and
60RIESGO
abrir
Metasploit600
IBM QRadar SIEM Unauthenticated Remote Code Execution
CVE-2018-141828 may 2018
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM
50RIESGO
abrir
Metasploit600
IBM QRadar SIEM Unauthenticated Remote Code Execution
CVE-2016-972228 may 2018
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r
43RIESGO
abrir
Exploit-DB
Werewolf Online 0.8.8 - Information Disclosure
CVE-2018-11505localandroid27 may 2018
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat outp
23RIESGO
abrir
Exploit-DB
Bitmain Antminer D3/L3+/S9 - Remote Command Execution
CVE-2018-11220remotehardware27 may 2018
Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.
28RIESGO
abrir
GitHub PoC141
编译好的脏牛漏洞(CVE-2016-5195)EXP
CVE-2016-5195HIGHbajo ataque27 may 2018
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DB
ClipperCMS 1.3.3 - Cross-Site Scripting
CVE-2018-11332webappsphp27 may 2018
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in
23RIESGO
abrir
anteriorpágina 899 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.