Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DB
Adobe Coldfusion 11.0.03.292866 - BlazeDS Java Object Deserialization Remote Code Execution
CVE-2017-3066CRITICALbajo ataqueremotewindows07 feb 2018
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir
GitHub PoC33
WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middleware. This is a Remote Code Execution vulnerability.
CVE-2017-10271HIGHbajo ataqueransomware07 feb 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2018-010107 feb 2018
A vulnerability in the Secure Sockets Layer (SSL) VPN functionality of the Cisco Adaptive Security Appliance (ASA) Softw
45RIESGO
abrir
Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Privilege Escalation
CVE-2018-6606localwindows07 feb 2018
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RIESGO
abrir
Exploit-DBVexDay Proof
Android - 'getpidcon' Permission Bypass in KeyStore Service
CVE-2017-13236dosandroid07 feb 2018
In the KeyStore service, there is a permissions bypass that allows access to protected resources. This could lead to loc
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2006-477706 feb 2018
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RIESGO
abrir
GitHub PoC82
CVE-2018-6389 Exploit In WordPress DoS
CVE-2018-638906 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC1
Apache RewriteRule to mitigate potential DoS attack via Wordpress wp-admin/load-scripts.php file
CVE-2018-638906 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
A ModSecurity ruleset for detecting potential attacks using CVE-2018-6389
CVE-2018-638906 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
Metasploit300
Claymore Dual GPU Miner Format String dos attack
CVE-2018-631706 feb 2018
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format strin
50RIESGO
abrir
GitHub PoC1
To solve CTFS.me problem
CVE-2016-10033CRITICALbajo ataque06 feb 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALbajo ataque06 feb 2018
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RIESGO
abrir
GitHub PoC
malware del lado del cliente de explotacion de vulnerabilidad de internet explorer 6.0 SP1 en windows xp SP2. No requiere de consentimiento por parte del usuario y no descarga ningun archivo
CVE-2006-477706 feb 2018
Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) fo
60RIESGO
abrir
Exploit-DBVexDay Proof
Apport/ABRT - 'chroot' Local Privilege Escalation (Metasploit)
CVE-2015-1318locallinux05 feb 2018
The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a craf
38RIESGO
abrir
Exploit-DB
Netis WF2419 Router - Cross-Site Scripting
CVE-2018-6190webappshardware05 feb 2018
Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.
23RIESGO
abrir
GitHub PoC90
Test and exploit for CVE-2017-12542
CVE-2017-1254205 feb 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir
Exploit-DB
Joomla! Component Zh GoogleMap 8.4.0.0 - SQL Injection
CVE-2018-6582webappsphp05 feb 2018
SQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails, ge
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0143HIGHbajo ataqueransomwareremotewindows05 feb 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
Wonder CMS 2.3.1 - Unrestricted File Upload
CVE-2017-14521webappsphp05 feb 2018
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0146HIGHbajo ataqueransomwareremotewindows05 feb 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-1254205 feb 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir
Exploit-DB
Joomla! Component Zh YandexMap 6.2.1.0 - 'id' SQL Injection
CVE-2018-6604webappsphp05 feb 2018
SQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetail
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'EternalRomance'/'EternalSynergy'/'EternalChampion' SMB Remote Code Execution (Metasploit) (MS17-010)
CVE-2017-0147HIGHbajo ataqueransomwareremotewindows05 feb 2018
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DB
Wonder CMS 2.3.1 - 'Host' Header Injection
CVE-2017-14523webappsphp05 feb 2018
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NO
23RIESGO
abrir
Exploit-DB
WordPress Core - 'load-scripts.php' Denial of Service
CVE-2018-6389dosphp05 feb 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
Exploit-DB
MalwareFox AntiMalware 2.74.0.150 - Local Privilege Escalation
CVE-2018-6593localwindows05 feb 2018
An issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows
23RIESGO
abrir
Exploit-DB
HPE iLO 4 < 2.53 - Add New Administrator User
CVE-2017-12542remotemultiple05 feb 2018
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53
60RIESGO
abrir
Exploit-DB
Online Voting System - Authentication Bypass
CVE-2018-6180webappsphp05 feb 2018
A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password fo
23RIESGO
abrir
Exploit-DB
Claymore Dual GPU Miner 10.5 - Format String
CVE-2018-6317dosmultiple05 feb 2018
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format strin
50RIESGO
abrir
Exploit-DB
Joomla! Component Zh BaiduMap 3.0.0.1 - SQL Injection
CVE-2018-6605webappsphp05 feb 2018
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, get
50RIESGO
abrir
anteriorpágina 923 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.