Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.964exploits catalogados
36.897CVEs con explotación pública
24.695probados en laboratorio
79.978 exploits
Exploit-DB
ERPnext 11 - Cross-Site Scripting
CVE-2018-11339webappsjava22 may 2018
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
23RIESGO
abrir
Exploit-DBVexDay Proof
AMD / ARM / Intel - Speculative Execution Variant 4 Speculative Store Bypass
CVE-2018-3639MEDIUMdoshardware22 may 2018
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RIESGO
abrir
GitHub PoC167
CVE-2018-8174 - VBScript memory corruption exploit.
CVE-2018-8174HIGHbajo ataqueransomware22 may 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-8174HIGHbajo ataqueransomware22 may 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
Exploit-DB
MakeMyTrip 7.2.4 - Information Disclosure
CVE-2018-11242localandroid22 may 2018
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypte
23RIESGO
abrir
Exploit-DB
Siemens SIMATIC S7-1500 CPU - Remote Denial of Service
CVE-2014-5074doslinux22 may 2018
Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device
23RIESGO
abrir
Exploit-DB
ManageEngine Recovery Manager Plus 5.3 - Cross-Site Scripting
CVE-2018-9163webappsjava21 may 2018
A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) all
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux 2.6.30 < 2.6.36-rc8 - Reliable Datagram Sockets (RDS) Privilege Escalation (Metasploit)
CVE-2010-3904HIGHbajo ataquelocallinux21 may 2018
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RIESGO
abrir
Exploit-DB
Schneider Electric PLCs - Cross-Site Request Forgery
CVE-2013-0663webappswindows21 may 2018
Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10
23RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 11 (Windows 7 x86/x64) - vbscript Code Execution
CVE-2018-8174HIGHbajo ataqueransomwarelocalwindows21 may 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC
My version - Easy File Sharing Web Server 7.2 - 'UserID' - Win 7 'DEP' bypass
CVE-2018-905920 may 2018
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir
Exploit-DB
D-Link DSL-3782 - Authentication Bypass
CVE-2018-8898webappshardware20 may 2018
A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B0
28RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8120HIGHbajo ataqueransomware19 may 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC499
CVE-2018-8120 Windows LPE exploit
CVE-2018-8120HIGHbajo ataqueransomware19 may 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC12
CVE-2018-11311 | mySCADA myPRO 7 Hardcoded FTP Username and Password Vulnerability
CVE-2018-1131119 may 2018
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack
28RIESGO
abrir
Exploit-DB
HPE iMC 7.3 - Remote Code Execution (Metasploit)
CVE-2017-8982remotewindows18 may 2018
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E05
28RIESGO
abrir
GitHub PoC12
CVE-2018-1111 DynoRoot
CVE-2018-1111HIGH18 may 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir
Exploit-DBVexDay Proof
DynoRoot DHCP Client - Command Injection
CVE-2018-1111HIGHlocallinux18 may 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir
Exploit-DB
HPE iMC 7.3 - Remote Code Execution (Metasploit)
CVE-2017-12500remotewindows18 may 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version PLAT 7.3 (E0504) was found
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Bound Check Elimination Bug
CVE-2018-0980doswindows18 may 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Exploit-DBVexDay Proof
Linux 4.8.0 < 4.8.0-46 - AF_PACKET packet_set_ring Privilege Escalation (Metasploit)
CVE-2017-7308locallinux18 may 2018
The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate cer
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-10562CRITICALbajo ataqueransomware17 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
Exploit-DBVexDay Proof
Jenkins CLI - HTTP Java Deserialization (Metasploit)
CVE-2016-9299remotelinux17 may 2018
The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a
60RIESGO
abrir
Exploit-DB
Intelbras NCLOUD 300 1.0 - Authentication bypass
CVE-2018-11094webappshardware17 may 2018
An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/Rebo
35RIESGO
abrir
Exploit-DBVexDay Proof
Nanopool Claymore Dual Miner 7.3 - Remote Code Execution
CVE-2018-1000049remotewindows17 may 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RIESGO
abrir
GitHub PoC163
bigric3/cve-2018-8120
CVE-2018-8120HIGHbajo ataqueransomware17 may 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Exploit-DB
Powerlogic/Schneider Electric IONXXXX Series - Cross-Site Request Forgery
CVE-2016-5809webappslinux17 may 2018
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series
23RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8120HIGHbajo ataqueransomware17 may 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache Struts 2 - Struts 1 Plugin Showcase OGNL Code Execution (Metasploit)
CVE-2017-9791CRITICALbajo ataqueremotemultiple17 may 2018
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
GitHub PoC13
Environment for DynoRoot (CVE-2018-1111)
CVE-2018-1111HIGH17 may 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir
anteriorpágina 902 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.