Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware20 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
Linux Kernel Version 4.14 - 4.4 (Ubuntu && Debian)
CVE-2017-1699519 mar 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
GitHub PoC
likekabin/CVE-2017-0213
CVE-2017-0213HIGHbajo ataqueransomware19 mar 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-7445CRITICALbajo ataque18 mar 2018
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remot
90RIESGO
abrir
Exploit-DB
Unitrends UEB 10.0 - Root Remote Code Execution
CVE-2018-6329remotelinux16 mar 2018
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RIESGO
abrir
Exploit-DB
Unitrends UEB 10.0 - Root Remote Code Execution
CVE-2018-6328remotelinux16 mar 2018
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, w
50RIESGO
abrir
Exploit-DBVexDay Proof
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
CVE-2017-5375remotewindows16 mar 2018
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
35RIESGO
abrir
Exploit-DBVexDay Proof
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
CVE-2016-1960remotewindows16 mar 2018
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox
35RIESGO
abrir
Exploit-DBVexDay Proof
Firefox 44.0.2 - ASM.JS JIT-Spray Remote Code Execution
CVE-2017-5375remotewindows16 mar 2018
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. T
35RIESGO
abrir
Exploit-DBVexDay Proof
Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
CVE-2016-2819remotewindows16 mar 2018
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to ex
28RIESGO
abrir
VulnCheck XDB
local
CVE-2018-6789CRITICALbajo ataqueransomware16 mar 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
GitHub PoC
CVE-2018-6789
CVE-2018-6789CRITICALbajo ataqueransomware16 mar 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
Exploit-DB
Linux Kernel < 4.4.0-116 (Ubuntu 16.04.4) - Local Privilege Escalation
CVE-2017-16995locallinux16 mar 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel (7 x86) - Local Privilege Escalation (MS17-017)
CVE-2017-0101HIGHbajo ataqueransomwarelocalwindows_x8615 mar 2018
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7
83RIESGO
abrir
Metasploit600
Mac OS X libxpc MITM Privilege Escalation
CVE-2018-423715 mar 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
43RIESGO
abrir
Metasploit0
Safari Proxy Object Type Confusion
CVE-2018-4233HIGH15 mar 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RIESGO
abrir
Metasploit0
Safari Proxy Object Type Confusion
CVE-2018-4404HIGH15 mar 2018
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improve
61RIESGO
abrir
Metasploit0
Safari Webkit Proxy Object Type Confusion
CVE-2018-4233HIGH15 mar 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RIESGO
abrir
Metasploit0
Safari Webkit Proxy Object Type Confusion
CVE-2017-1386115 mar 2018
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RIESGO
abrir
Exploit-DB
MikroTik RouterOS < 6.41.3/6.42rc27 - SMB Buffer Overflow
CVE-2018-7445CRITICALbajo ataqueremotehardware15 mar 2018
A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remot
90RIESGO
abrir
Exploit-DB
WordPress Plugin Duplicator 1.2.32 - Cross-Site Scripting
CVE-2018-7543webappsphp15 mar 2018
Cross-site scripting (XSS) vulnerability in installer/build/view.step4.php of the SnapCreek Duplicator plugin 1.2.32 for
23RIESGO
abrir
Exploit-DB
Spring Data REST < 2.6.9 (Ingalls SR9) / 3.0.1 (Kay SR1) - PATCH Request Remote Code Execution
CVE-2017-8046webappsjava15 mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
Exploit-DB
Android DRM Services - Buffer Overflow
CVE-2017-13253dosandroid15 mar 2018
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. Thi
23RIESGO
abrir
Exploit-DB
SAP NetWeaver AS JAVA CRM - Log injection Remote Command Execution
CVE-2018-2380MEDIUMbajo ataqueransomwareremotewindows14 mar 2018
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr
68RIESGO
abrir
Metasploit300
SAP Internet Graphics Server (IGS) XMLCHART XXE
CVE-2018-239314 mar 2018
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML Exter
23RIESGO
abrir
Metasploit300
SAP Internet Graphics Server (IGS) XMLCHART XXE
CVE-2018-239214 mar 2018
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML Exter
50RIESGO
abrir
Metasploit600
Unitrends Enterprise Backup bpserverd Privilege Escalation
CVE-2018-632914 mar 2018
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RIESGO
abrir
GitHub PoC51
PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM
CVE-2018-2380MEDIUMbajo ataqueransomware14 mar 2018
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr
68RIESGO
abrir
GitHub PoC2
Golang exploit for CVE-2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware14 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-2380MEDIUMbajo ataqueransomware14 mar 2018
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr
68RIESGO
abrir
anteriorpágina 915 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.