Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware14 mar 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
CVE-2018-7703webappsaspx13 mar 2018
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Tuleap 9.17.99.189 - Blind SQL Injection
CVE-2018-7538webappsphp13 mar 2018
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 a
23RIESGO
abrir
Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
CVE-2018-7701webappsaspx13 mar 2018
Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers
23RIESGO
abrir
Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
CVE-2018-7702webappsaspx13 mar 2018
SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e
28RIESGO
abrir
Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
CVE-2018-7704webappsaspx13 mar 2018
SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1
23RIESGO
abrir
Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
CVE-2018-7705webappsaspx13 mar 2018
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mai
23RIESGO
abrir
Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
CVE-2018-7706webappsaspx13 mar 2018
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbit
23RIESGO
abrir
Exploit-DB
SecurEnvoy SecurMail 9.1.501 - Multiple Vulnerabilities
CVE-2018-7707webappsaspx13 mar 2018
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitr
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-804612 mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
GitHub PoC37
PoC code for CVE-2017-13253
CVE-2017-1325312 mar 2018
In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. Thi
23RIESGO
abrir
GitHub PoC1
PoC for SpringBreak (CVE-2017-8046)
CVE-2017-804612 mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
Exploit-DB
DEWESoft X3 SP1 (x64) - Remote Command Execution
CVE-2018-7756remotewindows_x86-6412 mar 2018
RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-3066CRITICALbajo ataque12 mar 2018
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir
Exploit-DB
TextPattern 4.6.2 - 'qty' SQL Injection
CVE-2018-7474webappsphp12 mar 2018
An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on
23RIESGO
abrir
Exploit-DB
ManageEngine Applications Manager 13.5 - Remote Code Execution (Metasploit)
CVE-2018-7890webappsjava12 mar 2018
A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The pu
60RIESGO
abrir
GitHub PoC95
Exploitation Tool for CVE-2017-3066 targeting Adobe Coldfusion 11/12
CVE-2017-3066CRITICALbajo ataque12 mar 2018
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir
Exploit-DBVexDay Proof
Advantech WebAccess < 8.3 - Directory Traversal / Remote Code Execution
CVE-2017-16720webappswindows12 mar 2018
A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within th
35RIESGO
abrir
GitHub PoC
fibonascii/CVE-2004-0558
CVE-2004-055810 mar 2018
The Internet Printing Protocol (IPP) implementation in CUPS before 1.1.21 allows remote attackers to cause a denial of s
28RIESGO
abrir
Metasploit300
Flexense HTTP Server Denial Of Service
CVE-2018-806509 mar 2018
An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access v
60RIESGO
abrir
Exploit-DB
Bacula-Web < 8.0.0-rc2 - SQL Injection
CVE-2017-15367webappsphp09 mar 2018
Bacula-web before 8.0.0-rc2 is affected by multiple SQL Injection vulnerabilities that could allow an attacker to access
28RIESGO
abrir
GitHub PoC17
This is a Java program that exploits Spring Break vulnerability (CVE-2017-8046).
CVE-2017-804609 mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
Exploit-DB
WebLog Expert Enterprise 9.4 - Denial of Service
CVE-2018-7582doswindows09 mar 2018
WebLog Expert Web Server Enterprise 9.4 allows Remote Denial Of Service (daemon crash) via a long HTTP Accept Header to
35RIESGO
abrir
Exploit-DB
WebLog Expert Enterprise 9.4 - Authentication Bypass
CVE-2018-7581localwindows09 mar 2018
\ProgramData\WebLog Expert\WebServer\WebServer.cfg in WebLog Expert Web Server Enterprise 9.4 has weak permissions (BUIL
23RIESGO
abrir
GitHub PoC2
Exploit iOS 11.2.x by ZIMPERIUM and semi-completed by me. Sandbox escapes on CVE-2018-4087.
CVE-2018-408708 mar 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RIESGO
abrir
GitHub PoC14
WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk!
CVE-2017-804608 mar 2018
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
Exploit-DB
Memcached 1.5.5 - 'Memcrashed ' Insufficient Control of Network Message Volume Denial of Service With Shodan API
CVE-2018-1000115doslinux08 mar 2018
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RIESGO
abrir
Metasploit300
HTTP SickRage Password Leak
CVE-2018-916008 mar 2018
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RIESGO
abrir
Metasploit600
ManageEngine Applications Manager Remote Code Execution
CVE-2018-789007 mar 2018
A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The pu
60RIESGO
abrir
Exploit-DB
antMan 0.9.0c - Authentication Bypass
CVE-2018-7739webappsjava07 mar 2018
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and
35RIESGO
abrir
anteriorpágina 916 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.