Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
GitHub PoC17
a list of BIOS/Firmware fixes adressing CVE-2017-5715, CVE-2017-5753, CVE-2017-5754
CVE-2017-5715MEDIUM14 ene 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
GitHub PoC166
PoC for CVE-2018-0802 And CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware12 ene 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware12 ene 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DB
Kentico CMS 11.0 - Buffer Overflow
CVE-2018-5282doswindows12 ene 2018
Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password fie
23RIESGO
abrir
Exploit-DB
Xnami 1.0 - Cross-Site Scripting
CVE-2018-5370webappsphp12 ene 2018
BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-0802HIGHbajo ataqueransomware12 ene 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
GitHub PoC166
PoC for CVE-2018-0802 And CVE-2017-11882
CVE-2018-0802HIGHbajo ataqueransomware12 ene 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
GitHub PoC270
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
CVE-2018-0802HIGHbajo ataqueransomware11 ene 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
Exploit-DB
Seagate Personal Cloud - Multiple Vulnerabilities
CVE-2018-5347remotehardware11 ene 2018
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'AppendLeftOverItemsFromEndSegment' Out-of-Bounds Read
CVE-2018-0767doswindows11 ene 2018
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain info
35RIESGO
abrir
GitHub PoC68
Exploit the vulnerability to execute the calculator
CVE-2018-0802HIGHbajo ataqueransomware11 ene 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
Exploit-DBVexDay Proof
phpCollab 2.5.1 - File Upload (Metasploit)
CVE-2017-6090remotephp11 ene 2018
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RIESGO
abrir
Exploit-DB
ALLMediaServer 0.95 - Remote Buffer Overflow
CVE-2017-17932remotewindows11 ene 2018
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows SMB Server (v1/v2) - Mount Point Arbitrary Device Open Privilege Escalation
CVE-2018-0749doswindows11 ene 2018
The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware11 ene 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NTFS Owner/Mandatory Label Privilege Bypass
CVE-2018-0748doswindows11 ene 2018
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtImpersonateAnonymousToken LPAC to Non-LPAC Privilege Escalation
CVE-2018-0752doswindows11 ene 2018
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RIESGO
abrir
GitHub PoC270
PoC Exploit for CVE-2018-0802 (and optionally CVE-2017-11882)
CVE-2017-11882HIGHbajo ataqueransomware11 ene 2018
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DBVexDay Proof
Transmission - RPC DNS Rebinding
CVE-2018-5702remotemultiple11 ene 2018
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access con
28RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-0802HIGHbajo ataqueransomware11 ene 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-0802HIGHbajo ataqueransomware11 ene 2018
Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allow
93RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtImpersonateAnonymousToken AC to Non-AC Privilege Escalation
CVE-2018-0751doswindows11 ene 2018
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RIESGO
abrir
Exploit-DBVexDay Proof
Android - Hardware Service Manager Arbitrary Service Replacement due to getpidcon
CVE-2017-13209dosandroid11 ene 2018
In the ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the
23RIESGO
abrir
Exploit-DBVexDay Proof
macOS - 'process_policy' Stack Leak Through Uninitialized Field
CVE-2017-7154dosmacos11 ene 2018
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DB
WordPress Plugin Events Calendar - 'event_id' SQL Injection
CVE-2018-5315webappsphp10 ene 2018
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RIESGO
abrir
Exploit-DBVexDay Proof
HPE iMC - dbman 'RestoreDBase' Remote Command Execution (Metasploit)
CVE-2017-5817remotewindows10 ene 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-2386CRITICALbajo ataquewebappsmultiple10 ene 2018
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
Parity Browser < 1.6.10 - Bypass Same Origin Policy
CVE-2017-18016localmultiple10 ene 2018
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
23RIESGO
abrir
Exploit-DB
Jungo Windriver 12.5.1 - Local Privilege Escalation
CVE-2018-5189localwindows10 ene 2018
Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain syste
23RIESGO
abrir
Exploit-DB
DiskBoss Enterprise 8.8.16 - Remote Buffer Overflow
CVE-2018-5262remotewindows10 ene 2018
A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute
35RIESGO
abrir
anteriorpágina 928 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.