Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DB
Bravo Tejari Web Portal - Cross-Site Request Forgery
CVE-2018-7216webappsmultiple06 mar 2018
Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal al
23RIESGO
abrir
Exploit-DB
Softros Network Time System Server 2.3.4 - Denial of Service
CVE-2018-7658doswindows06 mar 2018
NTSServerSvc.exe in the server in Softros Network Time System 2.3.4 allows remote attackers to cause a denial of service
35RIESGO
abrir
Exploit-DB
ActivePDF Toolkit < 8.1.0.19023 - Multiple Memory Corruptions
CVE-2018-7264doswindows05 mar 2018
The Pictview image processing library embedded in the ActivePDF toolkit through 2018.1.0.18321 is prone to multiple out
28RIESGO
abrir
Exploit-DB
Suricata < 4.0.4 - IDS Detection Bypass
CVE-2018-6794dosmultiple05 mar 2018
Suricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious se
28RIESGO
abrir
Exploit-DB
Memcached 1.5.5 - 'Memcrashed' Insufficient Control Network Message Volume Denial of Service (1)
CVE-2018-1000115doslinux05 mar 2018
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RIESGO
abrir
GitHub PoC2
Tries to exploit a WordPress vulnerability (CVE-2018-6389) which can be used to cause a Denial of Service.
CVE-2018-638904 mar 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC131
Improved DOS exploit for wordpress websites (CVE-2018-6389)
CVE-2018-638904 mar 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
Metasploit600
ClipBucket beats_uploader Unauthenticated Arbitrary File Upload
CVE-2018-766503 mar 2018
An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter
23RIESGO
abrir
Exploit-DBVexDay Proof
uWSGI < 2.0.17 - Directory Traversal
CVE-2018-7490webappsphp02 mar 2018
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversa
50RIESGO
abrir
Exploit-DB
DualDesk 20 - 'Proxy.exe' Denial of Service
CVE-2018-7583doswindows02 mar 2018
Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500.
35RIESGO
abrir
Exploit-DB
antMan < 0.9.1a - Authentication Bypass
CVE-2018-7739webappsmultiple02 mar 2018
antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and
35RIESGO
abrir
Exploit-DB
TestLink Open Source Test Management < 1.9.16 - Remote Code Execution
CVE-2018-7466remotephp02 mar 2018
install/installNewDB.php in TestLink through 1.9.16 allows remote attackers to conduct injection attacks by leveraging c
23RIESGO
abrir
Exploit-DB
SEGGER embOS/IP FTP Server 3.22 - Denial of Service
CVE-2018-7449doswindows02 mar 2018
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in
23RIESGO
abrir
GitHub PoC8
Joomla - Component Google Map Landkarten <= 4.2.3 - SQL Injection
CVE-2018-639602 mar 2018
SQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a l
28RIESGO
abrir
Exploit-DB
D-Link DIR-600M Wireless - Cross-Site Scripting
CVE-2018-6936webappshardware02 mar 2018
Cross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.
23RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel (7 x86) - Local Privilege Escalation (MS16-039)
CVE-2016-0165HIGHbajo ataquelocalwindows_x8601 mar 2018
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
76RIESGO
abrir
GitHub PoC4
Source code and configuration files related to our article in MISC96
CVE-2017-512301 mar 2018
Insufficient data validation in waitid allowed an user to escape sandboxes on Linux.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware01 mar 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC1
cve-2017-10271
CVE-2017-10271HIGHbajo ataqueransomware01 mar 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC
Cisco iOS SNMP Overflow Exploit Toolkit (CVE-2017-6736)
CVE-2017-6736HIGHbajo ataque01 mar 2018
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RIESGO
abrir
GitHub PoC2
CVE-2018-6389 WordPress Core - 'load-scripts.php' Denial of Service <= 4.9.4
CVE-2018-638901 mar 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
alessiogilardi/PoC---CVE-2018-6389
CVE-2018-638928 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC1
This is a sort of Java porting of the Python exploit at: https://www.exploit-db.com/exploits/41570/.
CVE-2017-5638CRITICALbajo ataqueransomware28 feb 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC82
A sandbox escape based on the proof-of-concept (CVE-2018-4087) by Rani Idan (Zimperium)
CVE-2018-408728 feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple iOS 11.2.5 / watchOS 4.2.2 / tvOS 11.2.5 - 'bluetoothd' Memory Corruption
CVE-2018-4087dosmultiple28 feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware28 feb 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DBVexDay Proof
Routers2 2.24 - Cross-Site Scripting
CVE-2018-6193webappsperl28 feb 2018
A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph
23RIESGO
abrir
Exploit-DB
School Management Script 3.0.4 - Authentication Bypass
CVE-2018-7477webappsphp27 feb 2018
SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/
23RIESGO
abrir
Exploit-DBVexDay Proof
Asterisk chan_pjsip 15.2.0 - 'SUBSCRIBE' Stack Corruption
CVE-2018-7284doslinux27 feb 2018
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce
35RIESGO
abrir
Exploit-DB
CMS Made Simple 2.1.6 - Remote Code Execution
CVE-2018-7448webappsphp27 feb 2018
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote
28RIESGO
abrir
anteriorpágina 917 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.