Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware15 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
AMD Plays.tv 1.27.5.0 - 'plays_service.exe' Arbitrary File Execution
CVE-2018-6546localwindows15 abr 2018
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RIESGO
abrir
GitHub PoC7
Proof-of-Concept for Drupal CVE-2018-7600 / SA-CORE-2018-002
CVE-2018-7600CRITICALbajo ataqueransomware15 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC4
Testing and exploitation tool for Drupalgeddon 2 (CVE-2018-7600)
CVE-2018-7600CRITICALbajo ataqueransomware15 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC3
Tool to check for CVE-2018-7600 vulnerability on several URLS
CVE-2018-7600CRITICALbajo ataqueransomware15 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Metasploit600
Pi-Hole Whitelist OS Command Execution
CVE-2025-34087CRITICAL15 abr 2018
Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution
63RIESGO
abrir
GitHub PoC41
CVE-2018-6546-Exploit
CVE-2018-654615 abr 2018
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RIESGO
abrir
GitHub PoC4
PoC for CVE-2018-7600 Drupal SA-CORE-2018-002 (Drupalgeddon 2).
CVE-2018-7600CRITICALbajo ataqueransomware14 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC7
Drupal 0day Remote PHP Code Execution (Perl)
CVE-2018-7600CRITICALbajo ataqueransomware14 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC5
MSF exploit module for Drupalgeddon 2 (CVE-2018-7600 / SA-CORE-2018-002)
CVE-2018-7600CRITICALbajo ataqueransomware14 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware14 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware14 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC3
CVE-2018-7600 (Drupal)
CVE-2018-7600CRITICALbajo ataqueransomware13 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware13 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DBVexDay Proof
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution
CVE-2018-7600CRITICALbajo ataqueransomwarewebappsphp13 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1273CRITICALbajo ataqueransomware13 abr 2018
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir
Exploit-DB
MikroTik 6.41.4 - FTP daemon Denial of Service (PoC)
CVE-2018-10070doslinux13 abr 2018
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU a
28RIESGO
abrir
GitHub PoC10
Environment for CVE-2018-1273 (Spring Data Commons)
CVE-2018-1273CRITICALbajo ataqueransomware13 abr 2018
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property
100RIESGO
abrir
Exploit-DB
Microsoft Credential Security Support Provider - Remote Code Execution
CVE-2018-0886remotewindows13 abr 2018
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RIESGO
abrir
Exploit-DBVexDay Proof
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)
CVE-2018-7600CRITICALbajo ataqueransomwarewebappsphp13 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7600CRITICALbajo ataqueransomware12 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC603
Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)
CVE-2018-7600CRITICALbajo ataqueransomware12 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
Joomla! Convert Forms version 2.0.3 - Formula Injection (CSV Injection)
CVE-2018-10063webappsphp12 abr 2018
The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that
23RIESGO
abrir
GitHub PoC
Example exploit for CVE-2016-5195
CVE-2016-5195HIGHbajo ataque11 abr 2018
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Exploit-DB
DVD X Player Standard 5.5.3.9 - Buffer Overflow
CVE-2018-9128localwindows_x8610 abr 2018
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RIESGO
abrir
Exploit-DB
iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
CVE-2018-9236webappsphp10 abr 2018
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
23RIESGO
abrir
Exploit-DB
WordPress Plugin Activity Log 2.4.0 - Stored Cross-Site Scripting
CVE-2018-8729webappsphp10 abr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RIESGO
abrir
GitHub PoC14
Fixed No Virus Manual Automatic Loader exe no zip because zip picks up the anti virus detector.
CVE-2017-0213HIGHbajo ataqueransomware10 abr 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-9926webappsphp10 abr 2018
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=
23RIESGO
abrir
Exploit-DB
WordPress Plugin File Upload 4.3.2 - Stored Cross-Site Scripting
CVE-2018-9172webappsphp10 abr 2018
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
23RIESGO
abrir
anteriorpágina 910 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.