Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
VulnCheck XDB
infoleak
CVE-2016-2388MEDIUMbajo ataque10 ene 2018
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RIESGO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-2386CRITICALbajo ataquewebappsmultiple10 ene 2018
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Easydiscuss < 4.0.21 - Cross-Site Scripting
CVE-2018-5263webappsphp10 ene 2018
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
23RIESGO
abrir
Exploit-DB
DiskBoss Enterprise 8.8.16 - Remote Buffer Overflow
CVE-2018-5262remotewindows10 ene 2018
A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute
35RIESGO
abrir
Exploit-DBVexDay Proof
HPE iMC - dbman 'RestartDB' Remote Command Execution (Metasploit)
CVE-2017-5816remotewindows10 ene 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'Lowerer::LowerSetConcatStrMultiItem' Missing Integer Overflow Check
CVE-2018-0758doswindows10 ene 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RIESGO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-1910webappsmultiple10 ene 2018
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors,
23RIESGO
abrir
Exploit-DB
WordPress Plugin Events Calendar - 'event_id' SQL Injection
CVE-2018-5315webappsphp10 ene 2018
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RIESGO
abrir
Exploit-DB
Microsoft Office - 'Composite Moniker Remote Code Execution
CVE-2017-8570HIGHbajo ataquelocalwindows09 ene 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
GitHub PoC54
Spectre exploit
CVE-2017-5715MEDIUM09 ene 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQueryInformationProcess (information class 76_ QueryProcessEnergyValues)' Kernel Stack Memory Disclosure
CVE-2018-0745doswindows09 ene 2018
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an infor
23RIESGO
abrir
GitHub PoC9
8.4.1 Jailbreak using CVE-2016-4655 / CVE-2016-4656
CVE-2016-4655MEDIUMbajo ataque09 ene 2018
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir
GitHub PoC180
Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)
CVE-2019-18935CRITICALbajo ataqueransomware09 ene 2018
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC185
Proof of Concept exploit for CVE-2017-8570
CVE-2017-8570HIGHbajo ataque09 ene 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8570HIGHbajo ataque09 ene 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-11317CRITICALbajo ataque09 ene 2018
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Escape Analysis Bug
CVE-2017-11918doswindows09 ene 2018
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to
35RIESGO
abrir
GitHub PoC180
Telerik UI for ASP.NET AJAX File upload and .NET deserialisation exploit (CVE-2017-11317, CVE-2017-11357, CVE-2019-18935)
CVE-2017-11317CRITICALbajo ataque09 ene 2018
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'asm.js' Out-of-Bounds Read
CVE-2017-11911doswindows09 ene 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'nt!NtQuerySystemInformation (information class 138_ QueryMemoryTopologyInformation)' Kernel Pool Memory Disclosure
CVE-2018-0746doswindows09 ene 2018
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
23RIESGO
abrir
GitHub PoC11
TwonkyMedia Server 7.0.11-8.5 Directory Traversal CVE-2018-7171
CVE-2018-717109 ene 2018
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - BackwardPass::RemoveEmptyLoopAfterMemOp Does not Insert Branches
CVE-2017-11909doswindows09 ene 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Op_MaxInAnArray and Op_MinInAnArray can Explicitly call User-Defined JavaScript Functions
CVE-2017-11893doswindows09 ene 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execut
35RIESGO
abrir
Exploit-DB
Disk Pulse Enterprise 10.1.18 - Denial of Service
CVE-2017-15663doswindows08 ene 2018
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The att
28RIESGO
abrir
Exploit-DB
Synology DiskStation Manager (DSM) < 6.1.3-15152 - 'forget_passwd.cgi' User Enumeration
CVE-2017-9554webappscgi08 ene 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-16885webappshardware08 ene 2018
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining informati
35RIESGO
abrir
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-16887webappshardware08 ene 2018
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
35RIESGO
abrir
Exploit-DBVexDay Proof
VX Search Enterprise 10.1.12 - Denial of Service
CVE-2017-15662doswindows08 ene 2018
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RIESGO
abrir
Exploit-DB
Sync Breeze Enterprise 10.1.16 - Denial of Service
CVE-2017-15664doswindows08 ene 2018
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The at
23RIESGO
abrir
Exploit-DBVexDay Proof
Android - Inter-Process munmap due to Race Condition in ashmem
CVE-2017-13216dosandroid08 ene 2018
In ashmem_ioctl of ashmem.c, there is an out-of-bounds write due to insufficient locking when accessing asma. This could
23RIESGO
abrir
anteriorpágina 929 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.