Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DB
Photography CMS 1.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-5969webappsphp23 ene 2018
Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demons
23RIESGO
abrir
Exploit-DB
Flexible Poll 1.2 - SQL Injection
CVE-2018-5988webappsphp23 ene 2018
SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.
28RIESGO
abrir
Exploit-DB
RSVP Invitation Online 1.0 - Cross-Site Request Forgery (Update Admin)
CVE-2018-5976webappsphp23 ene 2018
Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modi
23RIESGO
abrir
Exploit-DBVexDay Proof
HP Connected Backup 8.6/8.8.6 - Local Privilege Escalation
CVE-2017-14355localwindows23 ene 2018
A potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6. The vulnerability
23RIESGO
abrir
Exploit-DB
Tumder 2.1 - SQL Injection
CVE-2018-5984webappsphp23 ene 2018
SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the categor
23RIESGO
abrir
Exploit-DB
AsusWRT Router < 3.0.0.4.380.7743 - LAN Remote Code Execution
CVE-2018-6000remotehardware22 ene 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn
60RIESGO
abrir
VulnCheck XDB
local
CVE-2018-100000122 ene 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir
Exploit-DB
AsusWRT Router < 3.0.0.4.380.7743 - LAN Remote Code Execution
CVE-2018-5999remotehardware22 ene 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro
60RIESGO
abrir
Metasploit600
AsusWRT LAN Unauthenticated Remote Code Execution
CVE-2018-599922 ene 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, pro
60RIESGO
abrir
Metasploit600
AsusWRT LAN Unauthenticated Remote Code Execution
CVE-2018-600022 ene 2018
An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpn
60RIESGO
abrir
GitHub PoC2
dewankpant/CVE-2017-16568
CVE-2017-1656821 ene 2018
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality.
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle JDeveloper 11.1.x/12.x - Directory Traversal
CVE-2017-10273webappsjava21 ene 2018
Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versi
23RIESGO
abrir
Exploit-DB
PHPFreeChat 1.7 - Denial of Service
CVE-2018-5954dosphp21 ene 2018
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect co
23RIESGO
abrir
Exploit-DB
Shopware 5.2.5/5.3 - Cross-Site Scripting
CVE-2017-15374webappsjson21 ene 2018
Shopware v5.2.5 - v5.3 is vulnerable to cross site scripting in the customer and order section of the content management
23RIESGO
abrir
Exploit-DB
OTRS 5.0.x/6.0.x - Remote Command Execution (1)
CVE-2017-16921webappsperl21 ene 2018
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.2
28RIESGO
abrir
GitHub PoC1
备忘:flash挂马工具备份 CVE-2018-4878
CVE-2018-4878HIGHbajo ataqueransomware20 ene 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
Exploit-DBVexDay Proof
macOS 10.13 (17A365) - Kernel Memory Disclosure due to Lack of Bounds Checking in 'AppleIntelCapriController::getDisplayPipeCapability'
CVE-2017-13878dosmacos19 ene 2018
An issue was discovered in certain Apple products. macOS before 10.13.2 is affected. The issue involves the "Intel Graph
23RIESGO
abrir
GitHub PoC
WebLogic wls-wsat RCE CVE-2017-10271
CVE-2017-10271HIGHbajo ataqueransomware19 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC7
cve-2017-10271 POC
CVE-2017-10271HIGHbajo ataqueransomware18 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
Primefaces 5.x - Remote Code Execution (Metasploit)
CVE-2017-1000486CRITICALbajo ataquewebappsjava18 ene 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
100RIESGO
abrir
Exploit-DB
Smiths Medical Medfusion 4000 - 'DHCP' Denial of Service
CVE-2017-12718doshardware18 ene 2018
A Classic Buffer Overflow issue was discovered in Smiths Medical Medfusion 4000 Wireless Syringe Infusion Pump, Version
28RIESGO
abrir
GitHub PoC1
Struts2 Application Vulnerable to CVE-2017-5638. Explains how the exploit of the vulnerability works in relation to OGNL and the JakartaMultiPart parser.
CVE-2017-5638CRITICALbajo ataqueransomware18 ene 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
Reservo Image Hosting Script 1.5 - Cross-Site Scripting
CVE-2018-5705webappsphp17 ene 2018
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to t
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptGeneratorFunction::GetPropertyBuiltIns' Type Confusion
CVE-2017-11914doswindows17 ene 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain t
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes (2)
CVE-2018-0775doswindows17 ene 2018
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
35RIESGO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-5723remotehardware17 ene 2018
MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
23RIESGO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-5726remotehardware17 ene 2018
MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request,
28RIESGO
abrir
Metasploit500
CloudMe Sync v1.10.9
CVE-2018-689217 ene 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'AsmJSByteCodeGenerator::EmitCall' Out-of-Bounds Read
CVE-2018-0780doswindows17 ene 2018
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtai
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Stack-to-Heap Copy
CVE-2018-0776doswindows17 ene 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RIESGO
abrir
anteriorpágina 926 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.