Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
GitHub PoC11
Al1ex/CVE-2017-7269
CVE-2017-7269CRITICALbajo ataque28 abr 2018
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7269CRITICALbajo ataque28 abr 2018
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware27 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7602CRITICALbajo ataqueransomware27 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7602CRITICALbajo ataqueransomware27 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-20149CRITICAL27 abr 2018
The Mikrotik RouterOS web server allows memory corruption in releases before Stable 6.38.5 and Long-term 6.37.5, aka Chi
48RIESGO
abrir
GitHub PoC6
POC to test/exploit drupal vulnerability SA-CORE-2018-004 / CVE-2018-7602
CVE-2018-7602CRITICALbajo ataqueransomware27 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
Exploit-DB
SickRage < v2018.03.09 - Clear-Text Credentials HTTP Response
CVE-2018-9160webappslinux26 abr 2018
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RIESGO
abrir
Metasploit600
GitList v0.6.0 Argument Injection Vulnerability
CVE-2018-100053326 abr 2018
klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in
40RIESGO
abrir
Exploit-DB
October CMS User Plugin 1.4.5 - Persistent Cross-Site Scripting
CVE-2018-10366webappsphp26 abr 2018
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam
23RIESGO
abrir
Exploit-DB
Frog CMS 0.9.5 - Persistent Cross-Site Scripting
CVE-2018-10321webappsphp26 abr 2018
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
23RIESGO
abrir
Exploit-DB
MyBB Threads to Link Plugin 1.3 - Cross-Site Scripting
CVE-2018-10365webappsphp26 abr 2018
An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the opt
23RIESGO
abrir
Exploit-DB
Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution
CVE-2016-10036webappslinux26 abr 2018
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RIESGO
abrir
GitHub PoC13
CVE-2017-16995(Ubuntu本地提权漏洞)
CVE-2017-1699526 abr 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
GitHub PoC
CVE-2018-9160
CVE-2018-916026 abr 2018
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RIESGO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - Local File Inclusion
CVE-2018-10260webappsphp25 abr 2018
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.
23RIESGO
abrir
Exploit-DBVexDay Proof
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code Execution (PoC)
CVE-2018-7602CRITICALbajo ataqueransomwarewebappsphp25 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - (Authenticated) Cross-Site Scripting
CVE-2018-10259webappsphp25 abr 2018
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged u
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-950625 abr 2018
The IconUriServlet of the Atlassian OAuth Plugin from version 1.3.0 before version 1.9.12 and from version 2.0.0 before
60RIESGO
abrir
Metasploit600
Apache Tika Header Command Injection
CVE-2018-133525 abr 2018
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Exploit-DB
Shopy Point of Sale 1.0 - CSV Injection
CVE-2018-10258webappsphp25 abr 2018
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to
23RIESGO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - CSV Injection
CVE-2018-10257webappsphp25 abr 2018
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RIESGO
abrir
Exploit-DB
HRSALE The Ultimate HRM 1.0.2 - 'award_id' SQL Injection
CVE-2018-10256webappsphp25 abr 2018
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privile
23RIESGO
abrir
Exploit-DB
Blog Master Pro 1.0 - CSV Injection
CVE-2018-10255webappsphp25 abr 2018
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level pri
23RIESGO
abrir
Exploit-DB
Easy File Sharing Web Server 7.2 - 'UserID' Remote Buffer Overflow (DEP Bypass)
CVE-2018-9059remotewindows24 abr 2018
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir
GitHub PoC2
Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware24 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery
CVE-2018-10312webappsphp24 abr 2018
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
23RIESGO
abrir
Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
CVE-2018-9245webappsphp24 abr 2018
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that a
23RIESGO
abrir
Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
CVE-2018-10285webappsphp24 abr 2018
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any
28RIESGO
abrir
Exploit-DB
Monstra CMS 3.0.4 - Arbitrary Folder Deletion
CVE-2018-9038webappsphp24 abr 2018
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uplo
23RIESGO
abrir
anteriorpágina 906 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.