Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-5724remotehardware17 ene 2018
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore
28RIESGO
abrir
Exploit-DB
Reservo Image Hosting Script 1.5 - Cross-Site Scripting
CVE-2018-5705webappsphp17 ene 2018
Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to t
23RIESGO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-5723remotehardware17 ene 2018
MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
23RIESGO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-5725remotehardware17 ene 2018
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of t
23RIESGO
abrir
Exploit-DB
Master IP CAM 01 - Multiple Vulnerabilities
CVE-2018-5726remotehardware17 ene 2018
MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request,
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JavascriptGeneratorFunction::GetPropertyBuiltIns' Type Confusion
CVE-2017-11914doswindows17 ene 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to gain t
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - Deferred Parsing Makes Wrong Scopes (2)
CVE-2018-0775doswindows17 ene 2018
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
35RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware16 ene 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC11
likekabin/CVE-2018-0802_CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware16 ene 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALbajo ataque16 ene 2018
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
Metasploit300
glibc 'realpath()' Privilege Escalation
CVE-2018-100000116 ene 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir
GitHub PoC178
Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)
CVE-2017-9248CRITICALbajo ataque16 ene 2018
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
GitHub PoC11
likekabin/CVE-2018-0802_CVE-2017-11882
CVE-2018-0802HIGHbajo ataqueransomware16 ene 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
Exploit-DBVexDay Proof
glibc < 2.26 - 'getcwd()' Local Privilege Escalation
CVE-2018-1000001locallinux16 ene 2018
In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before th
43RIESGO
abrir
GitHub PoC5
CVE-2017-10271 Weblogic 漏洞验证Poc及补丁
CVE-2017-10271HIGHbajo ataqueransomware16 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware16 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC
likekabin/CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware16 ene 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
GitHub PoC
Assesses a system for the "speculative execution" vulnerabilities described in CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
CVE-2017-5715MEDIUM15 ene 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
Exploit-DB
GitStack - Remote Code Execution
CVE-2018-5955webappsphp15 ene 2018
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RIESGO
abrir
Exploit-DB
PerfexCRM 1.9.7 - Arbitrary File Upload
CVE-2017-17976webappsphp15 ene 2018
In Utilities.php in Perfex CRM 1.9.7, Unrestricted file upload can lead to remote code execution.
28RIESGO
abrir
Exploit-DBVexDay Proof
Oracle E-Business Suite 12.1.3/12.2.x - Open Redirect
CVE-2017-3528webappsjsp15 ene 2018
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (li
43RIESGO
abrir
Metasploit300
GitStack Unauthenticated REST API Requests
CVE-2018-595515 ene 2018
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RIESGO
abrir
Exploit-DB
Disk Pulse Enterprise 10.1.18 - Remote Buffer Overflow
CVE-2017-15663remotewindows15 ene 2018
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The att
28RIESGO
abrir
Metasploit500
GitStack Unsanitized Argument RCE
CVE-2018-595515 ene 2018
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RIESGO
abrir
Exploit-DB
Oracle PeopleSoft 8.5x - Remote Code Execution
CVE-2017-10366webappsjava15 ene 2018
Vulnerability in the PeopleSoft Enterprise PT PeopleTools component of Oracle PeopleSoft Products (subcomponent: Perform
35RIESGO
abrir
Exploit-DB
ImgHosting 1.5 - Cross-Site Scripting
CVE-2018-5479webappsphp15 ene 2018
FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its sear
23RIESGO
abrir
Exploit-DB
SysGauge Server 3.6.18 - Remote Buffer Overflow
CVE-2018-5359remotewindows15 ene 2018
The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system
23RIESGO
abrir
Exploit-DB
pfSense < 2.1.4 - 'status_rrd_graph_img.php' Command Injection
CVE-2014-4688webappsphp15 ene 2018
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RIESGO
abrir
Exploit-DBVexDay Proof
ILIAS < 5.2.4 - Cross-Site Scripting
CVE-2018-5688webappsphp15 ene 2018
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in
23RIESGO
abrir
Exploit-DB
RISE 1.9 - 'search' SQL Injection
CVE-2017-17999webappsphp15 ene 2018
SQL injection vulnerability in RISE Ultimate Project Manager 1.9 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
anteriorpágina 927 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.