Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DBVexDay Proof
ASUS infosvr - Authentication Bypass Command Execution (Metasploit)
CVE-2014-9583remotehardware24 abr 2018
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RIESGO
abrir
Exploit-DB
Interspire Email Marketer < 6.1.6 - Remote Admin Authentication Bypass
CVE-2017-14322webappsphp24 abr 2018
The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior
35RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Overflow in Slab Rendering
CVE-2018-4935dosmultiple24 abr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RIESGO
abrir
GitHub PoC2
Tool to dive Apache logs for evidence of exploitation of CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware24 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Info Leak in Image Inflation
CVE-2018-4934dosmultiple24 abr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful expl
28RIESGO
abrir
Exploit-DB
Microsoft Windows - Local Privilege Escalation
CVE-2018-1038localwindows24 abr 2018
The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to
23RIESGO
abrir
Exploit-DB
VLC Media Player/Kodi/PopcornTime 'Red Chimera' < 2.2.5 - Memory Corruption (PoC)
CVE-2017-8311doswindows24 abr 2018
Potential heap based buffer overflow in ParseJSS in VideoLAN VLC before 2.2.5 due to skipping NULL terminator in an inpu
23RIESGO
abrir
Exploit-DB
Open-AudIT 2.1 - CSV Macro Injection
CVE-2018-9137webappswindows24 abr 2018
Open-AudIT before 2.2 has CSV Injection.
23RIESGO
abrir
Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
CVE-2018-10286webappsphp24 abr 2018
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and th
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Overflow when Playing Sound
CVE-2018-4936dosmultiple24 abr 2018
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable Heap Overflow vulnerability. Successful exploitat
28RIESGO
abrir
Exploit-DB
Monstra CMS 3.0.4 - Arbitrary Folder Deletion
CVE-2018-9038webappsphp24 abr 2018
Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uplo
23RIESGO
abrir
Exploit-DB
Ericsson-LG iPECS NMS A.1Ac - Cleartext Credential Disclosure
CVE-2018-10285webappsphp24 abr 2018
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any
28RIESGO
abrir
Exploit-DB
Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
CVE-2017-12635webappslinux23 abr 2018
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
GitHub PoC
herbiezimmerman/CVE-2017-11882-Possible-Remcos-Malspam
CVE-2017-11882HIGHbajo ataqueransomware23 abr 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DB
PRTG Network Monitor < 18.1.39.1648 - Stack Overflow (Denial of Service)
CVE-2018-10253doswindows_x8623 abr 2018
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
23RIESGO
abrir
Exploit-DB
phpMyAdmin 4.8.0 < 4.8.0-1 - Cross-Site Request Forgery
CVE-2018-10188webappsphp23 abr 2018
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_ope
23RIESGO
abrir
Exploit-DB
Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure
CVE-2018-9205webappsphp23 abr 2018
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
50RIESGO
abrir
Exploit-DB
Ncomputing vSpace Pro 10/11 - Directory Traversal
CVE-2018-10201webappswindows23 abr 2018
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible t
50RIESGO
abrir
Exploit-DB
Monstra cms 3.0.4 - Persitent Cross-Site Scripting
CVE-2018-10109webappsphp23 abr 2018
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
CVE-2018-2628CRITICALbajo ataqueremotemultiple22 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC
mudhappy/Wordpress-Hack-CVE-2018-6389
CVE-2018-638920 abr 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
Metasploit300
Foxit PDF Reader Pointer Overwrite UAF
CVE-2018-995820 abr 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir
Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
CVE-2018-8770webappsphp20 abr 2018
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro
50RIESGO
abrir
Metasploit300
Foxit PDF Reader Pointer Overwrite UAF
CVE-2018-994820 abr 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
GitHub PoC
CalderaForms 1.5.9.1 XSS (WordPress plugin) - tutorial
CVE-2018-774720 abr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RIESGO
abrir
Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
CVE-2018-8056webappsphp20 abr 2018
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/ma
28RIESGO
abrir
GitHub PoC1
xssfile/CVE-2017-8464-EXP
CVE-2017-8464HIGHbajo ataque20 abr 2018
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALbajo ataque20 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC2
Shadowshusky/CVE-2018-2628all
CVE-2018-2628CRITICALbajo ataque20 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC
shaoshore/CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque20 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
anteriorpágina 907 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.