Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DBVexDay Proof
Juju-run Agent - Privilege Escalation (Metasploit)
CVE-2017-9232locallinux12 feb 2018
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate pe
50RIESGO
abrir
Exploit-DBVexDay Proof
glibc - '$ORIGIN' Expansion Privilege Escalation (Metasploit)
CVE-2010-3847locallinux12 feb 2018
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RIESGO
abrir
Exploit-DBVexDay Proof
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
CVE-2010-3856locallinux12 feb 2018
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RIESGO
abrir
Exploit-DBVexDay Proof
glibc - 'LD_AUDIT' Arbitrary DSO Load Privilege Escalation (Metasploit)
CVE-2010-3847locallinux12 feb 2018
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not pro
38RIESGO
abrir
Exploit-DB
LibreOffice < 6.0.1 - '=WEBSERVICE' Remote Arbitrary File Disclosure
CVE-2018-6871remotelinux10 feb 2018
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a
28RIESGO
abrir
GitHub PoC86
Aggressor Script to launch IE driveby for CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware10 feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHbajo ataqueransomware10 feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHbajo ataqueransomware09 feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11826HIGHbajo ataque09 feb 2018
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Serv
93RIESGO
abrir
GitHub PoC2
Metasploit module for WordPress DOS load-scripts.php CVE-2018-638
CVE-2018-638909 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALbajo ataque09 feb 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC16
Ruby On Rails unrestricted render() exploit
CVE-2016-209809 feb 2018
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
GitHub PoC
Aggressor Script to just launch IE driveby for CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware09 feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
Exploit-DBVexDay Proof
macOS Kernel - Use-After-Free Due to Lack of Locking in 'AppleEmbeddedOSSupportHostClient::registerNotificationPort'
CVE-2018-4083dosmacos09 feb 2018
An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar S
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-12617HIGHbajo ataque09 feb 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC23
mdsecactivebreach/CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware09 feb 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC
Code put together from a few peoples ideas credit given don't use maliciously please
CVE-2017-12617HIGHbajo ataque09 feb 2018
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
GitHub PoC8
Exploit for CVE-2017-11826
CVE-2017-11826HIGHbajo ataque09 feb 2018
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Serv
93RIESGO
abrir
Metasploit600
Nanopool Claymore Dual Miner APIs RCE
CVE-2018-100004909 feb 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RIESGO
abrir
GitHub PoC6
PHPMailer < 5.2.18 Remote Code Execution Exploit
CVE-2016-10033CRITICALbajo ataque09 feb 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC2
Modification of Metasploit module for RCE in Ruby-On-Rails Console CVE-2015-3224
CVE-2015-322408 feb 2018
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-
50RIESGO
abrir
GitHub PoC55
A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.
CVE-2018-010108 feb 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RIESGO
abrir
GitHub PoC14
1337g/CVE-2018-0101-DOS-POC
CVE-2018-010107 feb 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RIESGO
abrir
Exploit-DBVexDay Proof
Asterisk 13.17.2 - 'chan_skinny' Remote Memory Corruption
CVE-2017-17090dosmultiple07 feb 2018
An issue was discovered in chan_skinny.c in Asterisk Open Source 13.18.2 and older, 14.7.2 and older, and 15.1.2 and old
45RIESGO
abrir
GitHub PoC33
WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote Code Execution vulnerability.
CVE-2017-10271HIGHbajo ataqueransomware07 feb 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DBVexDay Proof
Android - 'getpidcon' Permission Bypass in KeyStore Service
CVE-2017-13236dosandroid07 feb 2018
In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to loc
23RIESGO
abrir
Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Privilege Escalation
CVE-2018-6606localwindows07 feb 2018
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RIESGO
abrir
GitHub PoC18
MICROS Honeypot is a low interaction honeypot to detect CVE-2018-2636 in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (MICROS). This is a directory traversal vulnerability.
CVE-2018-263607 feb 2018
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RIESGO
abrir
Exploit-DB
Adobe Coldfusion 11.0.03.292866 - BlazeDS Java Object Deserialization Remote Code Execution
CVE-2017-3066CRITICALbajo ataqueremotewindows07 feb 2018
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2018-010107 feb 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RIESGO
abrir
anteriorpágina 922 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.