Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6229webappsjsp22 feb 2018
A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker
28RIESGO
abrir
Exploit-DB
Joomla! Component CW Tags 2.0.6 - SQL Injection
CVE-2018-7313webappsphp22 feb 2018
SQL Injection exists in the CW Tags 2.0.6 component for Joomla! via the searchtext array parameter.
28RIESGO
abrir
Exploit-DB
Joomla! Component Alexandria Book Library 3.1.2 - 'letter' SQL Injection
CVE-2018-7312webappsphp22 feb 2018
SQL Injection exists in the Alexandria Book Library 3.1.2 component for Joomla! via the letter parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6227webappsjsp22 feb 2018
A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to
23RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Email Encryption Gateway 5.5 (Build 1111.00) - Multiple Vulnerabilities
CVE-2018-6224webappsjsp22 feb 2018
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could a
23RIESGO
abrir
Exploit-DB
Joomla! Component OS Property Real Estate 3.12.7 - SQL Injection
CVE-2018-7319webappsphp22 feb 2018
SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system
23RIESGO
abrir
VulnCheck XDB
local
CVE-2017-1530322 feb 2018
In CPUID CPU-Z before 1.43, there is an arbitrary memory write that results directly in elevation of privileges, because
23RIESGO
abrir
Exploit-DB
Wavpack 5.1.0 - Denial of Service
CVE-2018-7254dosmultiple21 feb 2018
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of
23RIESGO
abrir
GitHub PoC1
RavSS/Bluetooth-Crash-CVE-2017-0785
CVE-2017-078521 feb 2018
A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.
28RIESGO
abrir
Exploit-DB
Disk Pulse Enterprise 10.4.18 - 'Import Command' Buffer Overflow (SEH)
CVE-2017-7310remotewindows21 feb 2018
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RIESGO
abrir
Exploit-DB
Disk Savvy Enterprise 10.4.18 - Buffer Overflow (SEH)
CVE-2018-6481remotewindows21 feb 2018
A buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to exe
28RIESGO
abrir
GitHub PoC59
CVE-2018-4087 PoC
CVE-2018-408721 feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. tvOS before 11.2.5 is affected. watchO
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - StorSvc SvcMoveFileInheritSecurity Arbitrary File Creation Privilege Escalation
CVE-2018-0826localwindows20 feb 2018
Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, versi
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'nt!RtlpCopyLegacyContextX86' Stack Memory Disclosure
CVE-2018-0832doswindows20 feb 2018
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Window
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - 'Js::RegexHelper::RegexReplace' Use-After-Free
CVE-2018-0866doswindows20 feb 2018
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NPFS Symlink Security Feature Bypass/Elevation of Privilege/Dangerous Behavior
CVE-2018-0823localwindows20 feb 2018
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Global Reparse Point Security Feature Bypass/Elevation of Privilege
CVE-2018-0822localwindows20 feb 2018
NTFS in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an eleva
23RIESGO
abrir
Exploit-DBVexDay Proof
MagniComp SysInfo - mcsiwrapper Privilege Escalation (Metasploit)
CVE-2017-6516localmultiple20 feb 2018
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Constrained Impersonation Capability Privilege Escalation
CVE-2018-0821localwindows20 feb 2018
AppContainer in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows
23RIESGO
abrir
GitHub PoC3
HanseSecure/CVE-2009-1437
CVE-2009-143719 feb 2018
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RIESGO
abrir
Exploit-DB
October CMS < 1.0.431 - Cross-Site Scripting
CVE-2018-7198webappsphp19 feb 2018
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
23RIESGO
abrir
GitHub PoC1
Wordpress Username Enumeration /CVE-2017-5487,WordPress < 4.7.1 -
CVE-2017-548717 feb 2018
wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before
45RIESGO
abrir
GitHub PoC1
Containerized exploitable PhpCollab
CVE-2017-609017 feb 2018
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Pinterest Clone Social Pinboard 2.0 - SQL Injection
CVE-2018-5987webappsphp16 feb 2018
SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id paramete
23RIESGO
abrir
Exploit-DB
Joomla! Component JS Jobs 1.1.9 - SQL Injection
CVE-2018-5994webappsphp16 feb 2018
SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or t
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Smart Shoutbox 3.0.0 - SQL Injection
CVE-2018-5975webappsphp16 feb 2018
SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI.
23RIESGO
abrir
Exploit-DB
Joomla! Component SimpleCalendar 3.1.9 - SQL Injection
CVE-2018-5974webappsphp16 feb 2018
SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Form Maker 3.6.12 - SQL Injection
CVE-2018-5991webappsphp16 feb 2018
SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats re
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Timetable Responsive Schedule For Joomla! 1.5 - 'alias' SQL Injection
CVE-2018-6583webappsphp16 feb 2018
SQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.
28RIESGO
abrir
Exploit-DBVexDay Proof
ABRT - 'raceabrt' Privilege Escalation (Metasploit)
CVE-2015-3315locallinux16 feb 2018
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac
38RIESGO
abrir
anteriorpágina 919 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.