Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
Exploit-DB
EasyService Billing 1.0 - Cross-Site Scripting
CVE-2018-11443webappsphp26 may 2018
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
23RIESGO
abrir
Exploit-DB
EasyService Billing 1.0 - 'q' SQL Injection
CVE-2018-11444webappsphp26 may 2018
A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
23RIESGO
abrir
Exploit-DB
EasyService Billing 1.0 - Cross-Site Request Forgery
CVE-2018-11442webappsphp26 may 2018
A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= U
23RIESGO
abrir
GitHub PoC4
Exploit for Remote Code Execution on GPON home routers (CVE-2018-10562) written in Python.
CVE-2018-10562CRITICALbajo ataqueransomware26 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-10562CRITICALbajo ataqueransomware26 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
Exploit-DB
EasyService Billing 1.0 - Cross-Site Request Forgery
CVE-2018-11445webappsphp26 may 2018
A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing
23RIESGO
abrir
GitHub PoC
soch4n/CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware25 may 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
SAP Internet Transaction Server 6200.x - Session Fixation / Cross-Site Scripting
CVE-2018-11415webappsmultiple25 may 2018
SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: th
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Cross Context Use-After-Free
CVE-2018-0946doswindows25 may 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RIESGO
abrir
Exploit-DBVexDay Proof
Oracle WebCenter Sites 11.1.1.8.0/12.2.1.x - Cross-Site Scripting
CVE-2018-2791webappsmultiple25 may 2018
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI). Supported
50RIESGO
abrir
Exploit-DBVexDay Proof
Skia and Firefox - Integer Overflow in SkTDArray Leading to Out-of-Bounds Write
CVE-2018-5159dosmultiple25 may 2018
An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks,
28RIESGO
abrir
GitHub PoC6
Flexense HTTP Server <= 10.6.24 - Denial Of Service Exploit
CVE-2018-806525 may 2018
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RIESGO
abrir
Exploit-DB
Oracle WebCenter FatWire Content Server < 7 - Improper Access Control
CVE-2017-10033webappslinux25 may 2018
Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Support Tools). Support
23RIESGO
abrir
Metasploit500
VLC Media Player MKV Use After Free
CVE-2018-1152924 may 2018
VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arb
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-15944CRITICALbajo ataque24 may 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
Metasploit600
Windscribe WindscribeService Named Pipe Privilege Escalation
CVE-2018-1147924 may 2018
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
38RIESGO
abrir
Exploit-DB
Honeywell XL Web Controller - Cross-Site Scripting
CVE-2014-3110webappslinux24 may 2018
Multiple cross-site scripting (XSS) vulnerabilities on Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earli
23RIESGO
abrir
GitHub PoC6
Detecion for the vulnerability CVE-2017-15944
CVE-2017-15944CRITICALbajo ataque24 may 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
Exploit-DB
Siemens SCALANCE S613 - Remote Denial of Service
CVE-2016-3963doslinux23 may 2018
Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 4
23RIESGO
abrir
Exploit-DBVexDay Proof
Samsung Galaxy S7 Edge - Overflow in OMACP WbXml String Extension Processing
CVE-2018-10751dosandroid23 may 2018
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Ex
23RIESGO
abrir
Metasploit300
MimiPenguin
CVE-2018-2078123 may 2018
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned f
18RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Magic Value Type Confusion
CVE-2018-0953doswindows22 may 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RIESGO
abrir
Exploit-DB
Siemens SIMATIC S7-1500 CPU - Remote Denial of Service
CVE-2014-5074doslinux22 may 2018
Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device
23RIESGO
abrir
Exploit-DB
MakeMyTrip 7.2.4 - Information Disclosure
CVE-2018-11242localandroid22 may 2018
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypte
23RIESGO
abrir
Exploit-DB
Siemens SIMATIC S7-1200 CPU - Cross-Site Scripting
CVE-2014-2908webappslinux22 may 2018
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1200 CPU devices 2.x and 3.x
43RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-8174HIGHbajo ataqueransomware22 may 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
Exploit-DB
ERPnext 11 - Cross-Site Scripting
CVE-2018-11339webappsjava22 may 2018
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux 4.4.0 < 4.4.0-53 - 'AF_PACKET chocobo_root' Local Privilege Escalation (Metasploit)
CVE-2016-8655locallinux22 may 2018
Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cau
43RIESGO
abrir
Exploit-DBVexDay Proof
AMD / ARM / Intel - Speculative Execution Variant 4 Speculative Store Bypass
CVE-2018-3639MEDIUMdoshardware22 may 2018
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RIESGO
abrir
GitHub PoC167
CVE-2018-8174 - VBScript memory corruption exploit.
CVE-2018-8174HIGHbajo ataqueransomware22 may 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
anteriorpágina 900 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.