Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DBVexDay Proof
Nanopool Claymore Dual Miner 7.3 - Remote Code Execution
CVE-2018-1000049remotewindows17 may 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RIESGO
abrir
GitHub PoC13
Environment for DynoRoot (CVE-2018-1111)
CVE-2018-1111HIGH17 may 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-10562CRITICALbajo ataqueransomware17 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
Exploit-DB
VirtueMart 3.1.14 - Persistent Cross-Site Scripting
CVE-2018-7465webappsphp16 may 2018
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by
23RIESGO
abrir
Exploit-DB
RSA Authentication Manager 8.2.1.4.0-build1394922 / < 8.3 P1 - XML External Entity Injection / Cross-Site Flashing / DOM Cross-Site Scripting
CVE-2018-1247webappsjava16 may 2018
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability
28RIESGO
abrir
Exploit-DBVexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
CVE-2015-3245locallinux16 may 2018
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir
Exploit-DB
totemomail Encryption Gateway 6.0.0 Build 371 - Cross-Site Request Forgery
CVE-2018-6563webappsasp16 may 2018
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow
23RIESGO
abrir
GitHub PoC5
Windows: heap overflow in jscript.dll in Array.sort
CVE-2017-1190716 may 2018
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RIESGO
abrir
Exploit-DBVexDay Proof
Libuser - 'roothelper' Local Privilege Escalation (Metasploit)
CVE-2015-3246MEDIUMbajo ataquelocallinux16 may 2018
libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly mod
78RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Token Process Trust SID Access Check Bypass Privilege Escalation
CVE-2018-8134localwindows16 may 2018
An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows
23RIESGO
abrir
Exploit-DB
Inteno IOPSYS 2.0 < 4.2.0 - 'p910nd' Remote Command Execution
CVE-2018-10123remotehardware16 may 2018
p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via reques
28RIESGO
abrir
Exploit-DB
Rockwell Scada System 27.011 - Cross-Site Scripting
CVE-2016-2279MEDIUMwebappswindows16 may 2018
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* bef
33RIESGO
abrir
Metasploit600
DHCP Client Command Injection (DynoRoot)
CVE-2018-1111HIGH15 may 2018
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir
GitHub PoC24
Exploit for Mass Remote Code Execution on GPON home routers (CVE-2018-10562) obtained from Shodan.
CVE-2018-10562CRITICALbajo ataqueransomware15 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
GitHub PoC
ISC INN 2.x - Command-Line Buffer Overflow
CVE-2001-144214 may 2018
Buffer overflow in innfeed for ISC InterNetNews (INN) before 2.3.0 allows local users in the "news" group to gain privil
23RIESGO
abrir
Exploit-DB
2345 Security Guard 3.7 - '2345NsProtect.sys' Denial of Service
CVE-2018-11034doswindows14 may 2018
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of ser
23RIESGO
abrir
Exploit-DB
WUZHI CMS 4.1.0 - 'tag[pinyin]' Cross-Site Scripting
CVE-2018-10311webappsphp13 may 2018
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitr
23RIESGO
abrir
GitHub PoC16
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - Remote Code Execution - Shell Script
CVE-2017-5638CRITICALbajo ataqueransomware13 may 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware13 may 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 2003 SP2 - 'RRAS' SMB Remote Code Execution
CVE-2017-11885remotewindows13 may 2018
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold,
35RIESGO
abrir
Exploit-DB
WUZHI CMS 4.1.0 - 'form[qq_10]' Cross-Site Scripting
CVE-2018-10313webappsphp13 may 2018
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set
23RIESGO
abrir
GitHub PoC4
The exploitation for CVE-2018-8897
CVE-2018-889713 may 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir
GitHub PoC423
Arbitrary code execution with kernel privileges using CVE-2018-8897.
CVE-2018-889713 may 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir
GitHub PoC2
gwolfs/CVE-2018-9995-ModifiedByGwolfs
CVE-2018-999511 may 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
Exploit-DB
Open-AudIT Professional - 2.1.1 - Cross-Site Scripting
CVE-2018-9155webappswindows11 may 2018
Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary we
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1029911 may 2018
An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), th
23RIESGO
abrir
Exploit-DB
Open-AudIT Community 2.2.0 - Cross-Site Scripting
CVE-2018-10314webappswindows11 may 2018
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Exploit-DB
2345 Security Guard 3.7 - '2345BdPcSafe.sys' Denial of Service
CVE-2018-10830doswindows11 may 2018
In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of serv
23RIESGO
abrir
GitHub PoC
SLRNPull Spool Directory Command Line Parameter Buffer Overflow Vulnerability
CVE-2002-074011 may 2018
Buffer overflow in slrnpull for the SLRN package, when installed setuid or setgid, allows local users to gain privileges
23RIESGO
abrir
GitHub PoC
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier
CVE-2002-099111 may 2018
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, all
23RIESGO
abrir
anteriorpágina 903 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.