Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
GitHub PoC
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier
CVE-2002-099111 may 2018
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, all
23RIESGO
abrir
Exploit-DBVexDay Proof
Mantis Bug Tracker 1.1.3 - 'manage_proj_page' PHP Code Execution (Metasploit)
CVE-2008-4687remotephp10 may 2018
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALbajo ataqueransomware10 may 2018
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC
CVE-2017-7494 C poc
CVE-2017-7494CRITICALbajo ataqueransomware10 may 2018
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
Exploit-DB
ModbusPal 1.6b - XML External Entity Injection
CVE-2018-10832webappsjava10 may 2018
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations c
23RIESGO
abrir
GitHub PoC81
Implements the POP/MOV SS (CVE-2018-8897) vulnerability by bugchecking the machine (local DoS).
CVE-2018-889710 may 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir
Exploit-DB
Fastweb FASTGate 0.00.47 - Cross-Site Request Forgery
CVE-2018-6023webappshardware10 may 2018
Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi act
23RIESGO
abrir
Exploit-DB
MyBB Latest Posts on Profile Plugin 1.1 - Cross-Site Scripting
CVE-2018-10580webappsphp10 may 2018
The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displ
23RIESGO
abrir
Exploit-DB
Dell Touchpad - 'ApMsgFwd.exe' Denial of Service
CVE-2018-10828doswindows10 may 2018
An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and wri
23RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-999509 may 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
Metasploit400
Windows SetImeInfoEx Win32k NULL Pointer Dereference
CVE-2018-8120HIGHbajo ataqueransomware09 may 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC2
DVR系列摄像头批量检测
CVE-2018-999509 may 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC4
CVE-2018-9995_Batch_scanning_exp
CVE-2018-999508 may 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
Exploit-DBVexDay Proof
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
CVE-2017-9101remotephp08 may 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RIESGO
abrir
Exploit-DBVexDay Proof
FTPShell Client 6.7 - Buffer Overflow
CVE-2018-7573remotewindows08 may 2018
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RIESGO
abrir
Exploit-DB
2345 Security Guard 3.7 - '2345NetFirewall.sys' Denial of Service
CVE-2018-10809doswindows_x8608 may 2018
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)
23RIESGO
abrir
Exploit-DBVexDay Proof
PlaySMS 1.4 - 'sendfromfile.php?Filename' (Authenticated) 'Code Execution (Metasploit)
CVE-2017-9080remotephp08 may 2018
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile
50RIESGO
abrir
Metasploit600
Microsoft Windows POP/MOV SS Local Privilege Elevation Vulnerability
CVE-2018-889708 may 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2018-999508 may 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC
CVE-2017-0411 PoC refered p0
CVE-2017-041108 may 2018
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to execute arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)
CVE-2017-15944CRITICALbajo ataqueremoteunix08 may 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
GitHub PoC
Python exploit for Remote Code Executuion on GPON home routers (CVE-2018-10562). Initially disclosed by VPNMentor (https://www.vpnmentor.com/blog/critical-vulnerability-gpon-router/), kudos for their work.
CVE-2018-10562CRITICALbajo ataqueransomware07 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
Exploit-DB
DeviceLock Plug and Play Auditor 5.72 - Unicode Buffer Overflow (SEH)
CVE-2018-10655localwindows06 may 2018
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RIESGO
abrir
Exploit-DB
CSP MySQL User Manager 2.3.1 - Authentication Bypass
CVE-2018-10757webappslinux06 may 2018
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a
23RIESGO
abrir
Exploit-DB
GNU wget - Cookie Injection
CVE-2018-0494locallinux06 may 2018
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequen
28RIESGO
abrir
GitHub PoC
CS4238 Computer Security Practices
CVE-2014-6271CRITICALbajo ataque05 may 2018
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
Exploit-DB
WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting
CVE-2018-10371webappsphp04 may 2018
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin
23RIESGO
abrir
Exploit-DB
IceWarp Mail Server < 11.1.1 - Directory Traversal
CVE-2015-1503webappsphp04 may 2018
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome V8 - Object Allocation Size Integer Overflow
CVE-2018-6065HIGHbajo ataqueremotemultiple04 may 2018
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows WMI - Recieve Notification Exploit (Metasploit)
CVE-2016-0040HIGHbajo ataquelocalwindows_x86-6404 may 2018
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir
anteriorpágina 904 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.