Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Microsoft Windows SMB Server (v1/v2) - Mount Point Arbitrary Device Open Privilege Escalation
CVE-2018-074911 ene 2018
The Microsoft Server Message Block (SMB) Server in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2
23RIESGO
abrir
Exploit-DB
macOS - 'process_policy' Stack Leak Through Uninitialized Field
CVE-2017-715411 ene 2018
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Exploit-DB
ALLMediaServer 0.95 - Remote Buffer Overflow
CVE-2017-1793211 ene 2018
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RIESGO
abrir
Exploit-DB
Microsoft Windows - NtImpersonateAnonymousToken AC to Non-AC Privilege Escalation
CVE-2018-075111 ene 2018
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RIESGO
abrir
Exploit-DB
phpCollab 2.5.1 - File Upload (Metasploit)
CVE-2017-609011 ene 2018
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authentica
60RIESGO
abrir
Exploit-DB
Microsoft Windows - NTFS Owner/Mandatory Label Privilege Bypass
CVE-2018-074811 ene 2018
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra - 'AppendLeftOverItemsFromEndSegment' Out-of-Bounds Read
CVE-2018-076711 ene 2018
Microsoft Edge in Microsoft Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain info
35RIESGO
abrir
Exploit-DB
Transmission - RPC DNS Rebinding
CVE-2018-570211 ene 2018
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access con
28RIESGO
abrir
Exploit-DB
Microsoft Windows - NtImpersonateAnonymousToken LPAC to Non-LPAC Privilege Escalation
CVE-2018-075211 ene 2018
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RIESGO
abrir
Exploit-DB
Seagate Personal Cloud - Multiple Vulnerabilities
CVE-2018-534711 ene 2018
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs
35RIESGO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-2386CRITICALbajo ataque10 ene 2018
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
Parity Browser < 1.6.10 - Bypass Same Origin Policy
CVE-2017-1801610 ene 2018
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
23RIESGO
abrir
Exploit-DB
WordPress Plugin Events Calendar - 'event_id' SQL Injection
CVE-2018-531510 ene 2018
The Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
23RIESGO
abrir
Exploit-DB
DiskBoss Enterprise 8.8.16 - Remote Buffer Overflow
CVE-2018-526210 ene 2018
A stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute
35RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - 'Lowerer::LowerSetConcatStrMultiItem' Missing Integer Overflow Check
CVE-2018-075810 ene 2018
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RIESGO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-2388MEDIUMbajo ataque10 ene 2018
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RIESGO
abrir
Exploit-DB
HPE iMC - dbman 'RestartDB' Remote Command Execution (Metasploit)
CVE-2017-581610 ene 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Exploit-DB
Muviko 1.1 - SQL Injection
CVE-2017-1797010 ene 2018
Multiple SQL injection vulnerabilities in Muviko 1.1 allow remote attackers to execute arbitrary SQL commands via the (1
23RIESGO
abrir
Exploit-DB
HPE iMC - dbman 'RestoreDBase' Remote Command Execution (Metasploit)
CVE-2017-581710 ene 2018
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Exploit-DB
SAP NetWeaver J2EE Engine 7.40 - SQL Injection
CVE-2016-191010 ene 2018
The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors,
23RIESGO
abrir
Exploit-DB
Joomla! Component Easydiscuss < 4.0.21 - Cross-Site Scripting
CVE-2018-526310 ene 2018
The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
23RIESGO
abrir
Exploit-DB
Jungo Windriver 12.5.1 - Local Privilege Escalation
CVE-2018-518910 ene 2018
Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain syste
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQuerySystemInformation (information class 138_ QueryMemoryTopologyInformation)' Kernel Pool Memory Disclosure
CVE-2018-074609 ene 2018
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationProcess (information class 76_ QueryProcessEnergyValues)' Kernel Stack Memory Disclosure
CVE-2018-074509 ene 2018
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an infor
23RIESGO
abrir
Exploit-DB
Microsoft Office - 'Composite Moniker Remote Code Execution
CVE-2017-8570HIGHbajo ataque09 ene 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - BackwardPass::RemoveEmptyLoopAfterMemOp Does not Insert Branches
CVE-2017-1190909 ene 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Op_MaxInAnArray and Op_MinInAnArray can Explicitly call User-Defined JavaScript Functions
CVE-2017-1189309 ene 2018
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execut
35RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra - 'asm.js' Out-of-Bounds Read
CVE-2017-1191109 ene 2018
ChakraCore and Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitrary code i
35RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Escape Analysis Bug
CVE-2017-1191809 ene 2018
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to
35RIESGO
abrir
Exploit-DB
Sync Breeze Enterprise 10.1.16 - Denial of Service
CVE-2017-1566408 ene 2018
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The at
23RIESGO
abrir
anteriorpágina 109 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.