Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
GitHub PoC2
Empire Port of CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware04 may 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DB
IceWarp Mail Server < 11.1.1 - Directory Traversal
CVE-2015-1503webappsphp04 may 2018
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RIESGO
abrir
Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
CVE-2018-10561CRITICALbajo ataqueremotehardware03 may 2018
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images
100RIESGO
abrir
Exploit-DB
JasperReports - (Authenticated) File Read
CVE-2018-5430HIGHbajo ataquewebappsmultiple03 may 2018
TIBCO JasperReports Server Information Disclosure Vulnerability
83RIESGO
abrir
GitHub PoC6
Ruby on Rails Web Console (v2) Whitelist Bypass Code Execution implementation in Python
CVE-2015-322403 may 2018
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
GitHub PoC114
Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch
CVE-2018-2628CRITICALbajo ataque03 may 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC9
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by "xlink:href=file://192.168.0.2/test.jpg" within an "office:document-content" element in a ".odt XML document".
CVE-2018-1058303 may 2018
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RIESGO
abrir
Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
CVE-2018-10562CRITICALbajo ataqueransomwareremotehardware03 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALbajo ataque03 may 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
Exploit-DB
Exim < 4.90.1 - 'base64d' Remote Code Execution
CVE-2018-6789CRITICALbajo ataqueransomwareremotelinux02 may 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
Exploit-DB
TBK DVR4104 / DVR4216 - Credentials Leak
CVE-2018-9995remotehardware02 may 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
Exploit-DB
Norton Core Secure WiFi Router - 'BLE' Command Injection (PoC)
CVE-2018-5234remotehardware02 may 2018
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RIESGO
abrir
Exploit-DB
Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
CVE-2018-9302webappsphp02 may 2018
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to r
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
CVE-2018-4200dosmultiple02 may 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RIESGO
abrir
Exploit-DB
LibreOffice/Open Office - '.odt' Information Disclosure
CVE-2018-10583localwindows02 may 2018
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RIESGO
abrir
Exploit-DB
WordPress Plugin Responsive Cookie Consent 1.7 / 1.6 / 1.5 - (Authenticated) Persistent Cross-Site Scripting
CVE-2018-10309webappsphp01 may 2018
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
23RIESGO
abrir
GitHub PoC31
PoC exploit for CVE-2018-5234
CVE-2018-523401 may 2018
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RIESGO
abrir
Metasploit300
LibreOffice 6.03 /Apache OpenOffice 4.1.5 Malicious ODT File Generator
CVE-2018-1058301 may 2018
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RIESGO
abrir
GitHub PoC1
Vuln checker for Drupal v7.x + v8.x (CVE-2018-7600 / SA-CORE-2018-002)
CVE-2018-7600CRITICALbajo ataqueransomware01 may 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8733webappsphp30 abr 2018
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8735webappsphp30 abr 2018
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RIESGO
abrir
Metasploit600
osCommerce Installer Unauthenticated Code Execution
CVE-2018-25114CRITICAL30 abr 2018
osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution
63RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules
CVE-2018-4139dosmacos30 abr 2018
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools"
23RIESGO
abrir
Exploit-DBVexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)
CVE-2018-7602CRITICALbajo ataqueransomwarewebappsphp30 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8734webappsphp30 abr 2018
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-8736webappsphp30 abr 2018
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Form Maker 1.12.20 - CSV Injection
CVE-2018-10504webappsphp30 abr 2018
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
CVE-2018-4206dosmultiple30 abr 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RIESGO
abrir
GitHub PoC558
(CVE-2018-9995) Get DVR Credentials
CVE-2018-999529 abr 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-999529 abr 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
anteriorpágina 905 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.