Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
VulnCheck XDB
initial-access
CVE-2009-1151CRITICALbajo ataque03 feb 2018
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RIESGO
abrir
GitHub PoC6
phpMyAdmin '/scripts/setup.php' PHP Code Injection RCE PoC (CVE-2009-1151)
CVE-2009-1151CRITICALbajo ataque03 feb 2018
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Subsystem for Linux - 'execve()' Local Privilege Escalation
CVE-2018-0743localwindows02 feb 2018
Windows Subsystem for Linux in Windows 10 version 1703, Windows 10 version 1709, and Windows Server, version 1709 allows
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Hospitality Simphony (MICROS) 2.7 < 2.9 - Directory Traversal
CVE-2018-2636webappsmultiple02 feb 2018
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RIESGO
abrir
Exploit-DBVexDay Proof
BMC Server Automation RSCD Agent - NSH Remote Command Execution (Metasploit)
CVE-2016-1542remotemultiple01 feb 2018
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'detachWrapper' Use-After-Free
CVE-2018-4089dosmultiple01 feb 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. Safa
23RIESGO
abrir
Exploit-DBVexDay Proof
BMC Server Automation RSCD Agent - NSH Remote Command Execution (Metasploit)
CVE-2016-1543remotemultiple01 feb 2018
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a
60RIESGO
abrir
Exploit-DB
Joomla! Component Visual Calendar 3.1.3 - 'id' SQL Injection
CVE-2018-6395webappsphp30 ene 2018
SQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
23RIESGO
abrir
Exploit-DB
System Shield 5.0.0.136 - Privilege Escalation
CVE-2018-5701localwindows30 ene 2018
In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerabi
28RIESGO
abrir
Exploit-DB
Joomla! Component CP Event Calendar 3.0.1 - 'id' SQL Injection
CVE-2018-6398webappsphp30 ene 2018
SQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
23RIESGO
abrir
Exploit-DB
BMC BladeLogic RSCD Agent 8.3.00.64 - Windows Users Disclosure
CVE-2016-5063webappswindows30 ene 2018
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RIESGO
abrir
Exploit-DB
HPE iMC 7.3 - RMI Java Deserialization
CVE-2017-5792remotewindows30 ene 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
35RIESGO
abrir
Exploit-DB
Joomla! Component Picture Calendar for Joomla! 3.1.4 - Directory Traversal
CVE-2018-6397webappsphp30 ene 2018
Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter.
28RIESGO
abrir
Exploit-DB
Hotspot Shield - Information Disclosure
CVE-2018-6460localwindows30 ene 2018
Hotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sen
28RIESGO
abrir
Exploit-DB
Advantech WebAccess < 8.3 - SQL Injection
CVE-2017-16716webappswindows30 ene 2018
A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs
23RIESGO
abrir
GitHub PoC22
ERPScan Public POC for CVE-2018-2636
CVE-2018-263629 ene 2018
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RIESGO
abrir
Exploit-DB
Arq 5.10 - Local Privilege Escalation (1)
CVE-2017-16928localmacos29 ene 2018
The arq_updater binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequently g
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle WebLogic - wls-wsat Component Deserialization Remote Code Execution (Metasploit)
CVE-2017-10271HIGHbajo ataqueransomwareremotemultiple29 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DBVexDay Proof
macOS - 'sysctl_vfs_generic_conf' Stack Leak Through Struct Padding
CVE-2018-4090dosmacos29 ene 2018
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS
23RIESGO
abrir
Exploit-DB
Arq 5.10 - Local Privilege Escalation (2)
CVE-2017-16945localmacos29 ene 2018
The standardrestorer binary in Arq 5.10 and earlier for Mac allows local users to write to arbitrary files and consequen
23RIESGO
abrir
Exploit-DB
systemd (systemd-tmpfiles) < 236 - 'fs.protected_hardlinks=0' Local Privilege Escalation
CVE-2017-18078locallinux29 ene 2018
systemd-tmpfiles in systemd before 237 attempts to support ownership/permission changes on hardlinked files even if the
23RIESGO
abrir
Exploit-DB
iBall WRA150N - Multiple Vulnerabilities
CVE-2018-6388webappshardware29 ene 2018
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands
23RIESGO
abrir
Exploit-DB
Joomla! Component JS Support Ticket 1.1.0 - Cross-Site Request Forgery
CVE-2018-6007webappsphp28 ene 2018
CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.
23RIESGO
abrir
Exploit-DB
Artifex MuJS 1.0.2 - Denial of Service
CVE-2018-6191dosmultiple28 ene 2018
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent v
23RIESGO
abrir
Exploit-DB
TSiteBuilder 1.0 - SQL Injection
CVE-2018-6365webappsphp28 ene 2018
SQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware28 ene 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
KeystoneJS < 4.0.0-beta.7 - Cross-Site Request Forgery
CVE-2017-16570webappsnodejs28 ene 2018
KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureL
23RIESGO
abrir
Exploit-DB
Artifex MuJS 1.0.2 - Integer Overflow
CVE-2018-5759dosmultiple28 ene 2018
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re
23RIESGO
abrir
GitHub PoC
Working POC for CVE 2017-5638
CVE-2017-5638CRITICALbajo ataqueransomware28 ene 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
Hot Scripts Clone - 'subctid' SQL Injection
CVE-2017-17612webappsphp28 ene 2018
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
23RIESGO
abrir
anteriorpágina 924 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.