Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DBVexDay Proof
Microsoft Windows Defender - 'mpengine.dll' Memory Corruption
CVE-2018-0986doswindows05 abr 2018
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a speci
35RIESGO
abrir
Exploit-DB
Joomla! Component JS Jobs 1.2.0 - Cross-Site Scripting
CVE-2018-9183webappsphp05 abr 2018
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.
23RIESGO
abrir
Exploit-DB
WebRTC - Private IP Leakage (Metasploit)
CVE-2018-6849webappsmultiple05 abr 2018
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client informati
43RIESGO
abrir
Exploit-DB
GetSimple CMS 3.3.13 - Cross-Site Scripting
CVE-2018-9173webappsphp05 abr 2018
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows rem
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHbajo ataqueransomware04 abr 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC7
Flash Exploit Poc
CVE-2018-4878HIGHbajo ataqueransomware04 abr 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (1)
CVE-2018-0934doswindows03 abr 2018
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (2)
CVE-2018-0934doswindows03 abr 2018
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (1)
CVE-2018-0933doswindows03 abr 2018
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RIESGO
abrir
GitHub PoC
Phusion WebServer 1.0 - Directory Traversal
CVE-2002-028803 abr 2018
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RIESGO
abrir
GitHub PoC
Phusion WebServer 1.0 - 'URL' Remote Buffer Overflow
CVE-2002-028903 abr 2018
Buffer overflow in Phusion web server 1.0 allows remote attackers to cause a denial of service and execute arbitrary cod
28RIESGO
abrir
GitHub PoC
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow.
CVE-2002-020103 abr 2018
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute a
28RIESGO
abrir
GitHub PoC
Xerver 2.10 - Multiple Request Denial of Service Vulnerabilities
CVE-2002-044803 abr 2018
Xerver Free Web Server 2.10 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request
28RIESGO
abrir
GitHub PoC
Airsensor M520 - HTTPd Unauthenticated Remote Denial of Service / Buffer Overflow (PoC)
CVE-2007-503603 abr 2018
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RIESGO
abrir
GitHub PoC
Cooolsoft PowerFTP Server 2.0 3/2.10 - Multiple Denial of Service Vulnerabilities
CVE-2001-093203 abr 2018
Buffer overflow in Cooolsoft PowerFTP Server 2.03 allows remote attackers to cause a denial of service and possibly exec
28RIESGO
abrir
GitHub PoC
Nortel Wireless LAN Access Point 2200 Series - Denial of Service
CVE-2004-254903 abr 2018
Nortel Wireless LAN (WLAN) Access Point (AP) 2220, 2221, and 2225 allow remote attackers to cause a denial of service (s
28RIESGO
abrir
GitHub PoC
March Networks DVR 3204 - Logfile Information Disclosure
CVE-2007-663803 abr 2018
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows r
28RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome V8 - 'ElementsAccessorBase::CollectValuesOrEntriesImpl' Type Confusion
CVE-2018-6064dosmultiple03 abr 2018
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote
23RIESGO
abrir
Exploit-DB
DLink DIR-601 - Admin Password Disclosure
CVE-2018-5708webappshardware02 abr 2018
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticat
23RIESGO
abrir
GitHub PoC
Cisco VPN Client - Integer Overflow Denial of Service
CVE-2009-411802 abr 2018
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RIESGO
abrir
GitHub PoC267
A code demonstrating CVE-2018-0886
CVE-2018-088602 abr 2018
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RIESGO
abrir
Exploit-DB
OpenCMS 10.5.3 - Cross-Site Scripting
CVE-2018-8815webappsphp02 abr 2018
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in
23RIESGO
abrir
Exploit-DBVexDay Proof
WampServer 3.1.1 - Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-8732webappsphp02 abr 2018
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or H
23RIESGO
abrir
Exploit-DBVexDay Proof
WampServer 3.1.2 - Cross-Site Request Forgery
CVE-2018-8817webappsphp02 abr 2018
Wampserver before 3.1.3 has CSRF in add_vhost.php.
23RIESGO
abrir
Exploit-DB
Frog CMS 0.9.5 - Cross-Site Request Forgery (Add User)
CVE-2018-8908webappsphp02 abr 2018
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CS
23RIESGO
abrir
Exploit-DB
OpenCMS 10.5.3 - Cross-Site Request Forgery
CVE-2018-8811webappsphp02 abr 2018
Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allow
23RIESGO
abrir
GitHub PoC49
An implementation of CVE-2016-0974 for the Nintendo Wii.
CVE-2016-097401 abr 2018
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
35RIESGO
abrir
GitHub PoC
tomcat7.x远程命令执行
CVE-2017-12615HIGHbajo ataqueransomware01 abr 2018
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
Exploit-DB
WordPress Plugin Relevanssi 4.0.4 - Reflected Cross-Site Scripting
CVE-2018-9034webappsphp30 mar 2018
Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote
23RIESGO
abrir
Exploit-DB
WordPress Plugin WP Security Audit Log 3.1.1 - Sensitive Information Disclosure
CVE-2018-8719webappsphp30 mar 2018
An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-securit
43RIESGO
abrir
anteriorpágina 912 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.