Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DB
Acrolinx Server < 5.2.5 - Directory Traversal
CVE-2018-7719remotewindows26 mar 2018
Acrolinx Server before 5.2.5 on Windows allows Directory Traversal.
50RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
CVE-2017-13261dosandroid23 mar 2018
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. T
23RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
CVE-2017-13260dosandroid23 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RIESGO
abrir
Exploit-DBVexDay Proof
Dell EMC NetWorker - Denial of Service
CVE-2018-1218doslinux23 mar 2018
In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the '
28RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
CVE-2017-13262dosandroid23 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
CVE-2017-13258dosandroid23 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
CVE-2017-13258dosandroid23 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
CVE-2017-13260dosandroid23 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
CVE-2017-13261dosandroid23 mar 2018
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. T
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Site Editor 1.1.1 - Local File Inclusion
CVE-2018-7422webappsphp23 mar 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
CVE-2017-13262dosandroid23 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RIESGO
abrir
Exploit-DB
Linux Kernel < 4.15.4 - 'show_floppy' KASLR Address Leak
CVE-2018-7273locallinux22 mar 2018
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RIESGO
abrir
GitHub PoC
likekabin/CVE-2017-0199
CVE-2017-0199HIGHbajo ataqueransomware22 mar 2018
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Window
100RIESGO
abrir
GitHub PoC1
A version of CVE-2017-0213 that I plan to use with an Empire stager
CVE-2017-0213HIGHbajo ataqueransomware21 mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
VulnCheck XDB
local
CVE-2017-0213HIGHbajo ataqueransomware21 mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
Exploit-DB
Cisco node-jos < 0.11.0 - Re-sign Tokens
CVE-2018-0114webappsmultiple20 mar 2018
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Desktop Bridge VFS Privilege Escalation
CVE-2018-0877localwindows_x86-6420 mar 2018
The Desktop Bridge Virtual File System (VFS) in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server,
23RIESGO
abrir
Exploit-DB
Intelbras Telefone IP TIP200 LITE - Local File Disclosure
CVE-2018-9010webappshardware20 mar 2018
Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via t
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware20 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
Vehicle Sales Management System - Multiple Vulnerabilities
CVE-2017-1000474webappsphp20 mar 2018
Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/veh
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'NtQueryVirtualMemory(MemoryMappedFilenameInformation)' 64-bit Pool Memory Disclosure
CVE-2018-0894doswindows_x86-6420 mar 2018
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'nt!KiDispatchException' 64-bit Stack Memory Disclosure
CVE-2018-0897doswindows_x86-6420 mar 2018
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'nt!NtWaitForDebugEvent' 64-bit Stack Memory Disclosure
CVE-2018-0901doswindows_x86-6420 mar 2018
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RIESGO
abrir
GitHub PoC1
Apache Struts CVE-2017-5638 RCE exploitation
CVE-2017-5638CRITICALbajo ataqueransomware20 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'NtQueryInformationThread(ThreadBasicInformation)' 64-bit Stack Memory Disclosure
CVE-2018-0895doswindows_x86-6420 mar 2018
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RIESGO
abrir
Exploit-DB
Coship RT3052 Wireless Router - Persistent Cross-Site Scripting
CVE-2018-8772webappshardware20 mar 2018
Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.
23RIESGO
abrir
GitHub PoC26
This repository contains the POC of an exploit for node-jose < 0.11.0
CVE-2018-011420 mar 2018
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Desktop Bridge Virtual Registry NtLoadKey Arbitrary File Read/Write Privilege Escalation
CVE-2018-0882localwindows20 mar 2018
The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an el
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Software Updater macOS - Unsafe use of Distributed Objects Privilege Escalation
CVE-2018-6084localmacos20 mar 2018
Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local
23RIESGO
abrir
Exploit-DBVexDay Proof
Internet Explorer - 'RegExp.lastMatch' Memory Disclosure
CVE-2018-0891doswindows20 mar 2018
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT
28RIESGO
abrir
anteriorpágina 914 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.