Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DBVexDay Proof
Microsoft Windows 8.1/2012 R2 - SMBv3 Null Pointer Dereference Denial of Service
CVE-2018-0833doswindows27 feb 2018
The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2
35RIESGO
abrir
Exploit-DB
Concrete5 CMS < 8.3.0 - Username / Comments Enumeration
CVE-2017-18195webappsphp27 feb 2018
An issue was discovered in tools/conversations/view_ajax.php in Concrete5 before 8.3.0. An unauthenticated user can enum
28RIESGO
abrir
Metasploit300
Memcached Stats Amplification Scanner
CVE-2018-100011527 feb 2018
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RIESGO
abrir
Exploit-DBVexDay Proof
Asterisk chan_pjsip 15.2.0 - 'INVITE' Denial of Service
CVE-2018-7286doslinux27 feb 2018
An issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Certified Asteris
35RIESGO
abrir
GitHub PoC
MaxSecurity/Office-CVE-2017-8570
CVE-2017-8570HIGHbajo ataque26 feb 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
GitHub PoC
BlackRouter/cve-2018-6389
CVE-2018-638926 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
Exploit-DBVexDay Proof
AsusWRT LAN - Remote Code Execution (Metasploit)
CVE-2018-6000remotehardware26 feb 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn
60RIESGO
abrir
Exploit-DBVexDay Proof
AsusWRT LAN - Remote Code Execution (Metasploit)
CVE-2018-5999remotehardware26 feb 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8570HIGHbajo ataque26 feb 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
Exploit-DBVexDay Proof
CloudMe Sync 1.10.9 - Stack-Based Buffer Overflow (Metasploit)
CVE-2018-6892remotewindows26 feb 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
GitHub PoC
Proof of Concept of vunerability CVE-2018-6389 on Wordpress 4.9.2
CVE-2018-638925 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
CVE-2018-4878 样本
CVE-2018-4878HIGHbajo ataqueransomware23 feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHbajo ataqueransomware23 feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6226webappsjsp22 feb 2018
Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files
23RIESGO
abrir
Exploit-DB
NoMachine < 6.0.80 (x64) - 'nxfuse' Privilege Escalation
CVE-2018-6947localwindows_x86-6422 feb 2018
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM
23RIESGO
abrir
Exploit-DB
Joomla! Component PrayerCenter 3.0.2 - 'sessionid' SQL Injection
CVE-2018-7314webappsphp22 feb 2018
SQL Injection exists in the PrayerCenter 3.0.2 component for Joomla! via the sessionid parameter, a different vulnerabil
50RIESGO
abrir
Exploit-DB
Joomla! Component Proclaim 9.1.1 - Arbitrary File Upload
CVE-2018-7316webappsphp22 feb 2018
Arbitrary File Upload exists in the Proclaim 9.1.1 component for Joomla! via a mediafileform action.
23RIESGO
abrir
Exploit-DB
Joomla! Component Proclaim 9.1.1 - Backup File Download
CVE-2018-7317webappsphp22 feb 2018
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
23RIESGO
abrir
Exploit-DB
Joomla! Component CheckList 1.1.1 - SQL Injection
CVE-2018-7318webappsphp22 feb 2018
SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, descrip
23RIESGO
abrir
Exploit-DB
NoMachine < 6.0.80 (x86) - 'nxfuse' Privilege Escalation
CVE-2018-6947localwindows_x8622 feb 2018
An uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoM
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6223webappsjsp22 feb 2018
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allo
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6225webappsjsp22 feb 2018
An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenti
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6224webappsjsp22 feb 2018
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could a
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6227webappsjsp22 feb 2018
A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to
23RIESGO
abrir
VulnCheck XDB
local
CVE-2017-1530322 feb 2018
In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6221webappsjsp22 feb 2018
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6219webappsjsp22 feb 2018
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdr
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6222webappsjsp22 feb 2018
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log fi
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6220webappsjsp22 feb 2018
An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6228webappsjsp22 feb 2018
A SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to exe
28RIESGO
abrir
anteriorpágina 918 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.