Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Unitrends UEB - HTTP API Remote Code Execution (Metasploit)
CVE-2018-6328remotelinux08 oct 2018
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, w
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Net-NTLMv2 Reflection DCOM/RPC (Metasploit)
CVE-2016-3225localwindows08 oct 2018
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
50RIESGO
abrir
Exploit-DBVexDay Proof
Android - sdcardfs Changes current->fs Without Proper Locking
CVE-2018-9515dosandroid08 oct 2018
In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This co
23RIESGO
abrir
Exploit-DBVexDay Proof
Zahir Enterprise Plus 6 - Stack Buffer Overflow (Metasploit)
CVE-2018-17408localwindows08 oct 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RIESGO
abrir
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17440webappsphp05 oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves b
35RIESGO
abrir
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17442webappsphp05 oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerabili
28RIESGO
abrir
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17443webappsphp05 oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateS
23RIESGO
abrir
Exploit-DBVexDay Proof
D-Link Central WiFiManager Software Controller 1.03 - Multiple Vulnerabilities
CVE-2018-17441webappsphp05 oct 2018
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser
23RIESGO
abrir
Exploit-DBVexDay Proof
PCProtect 4.8.35 - Privilege Escalation
CVE-2018-17776localwindows_x86-6428 sep 2018
PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8469remotewindows27 sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8468remotewindows27 sep 2018
An elevation of privilege vulnerability exists when Windows, allowing a sandbox escape, aka "Windows Elevation of Privil
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Sandbox Escape
CVE-2018-8463remotewindows27 sep 2018
An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppCont
28RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel - VMA Use-After-Free via Buggy vmacache_flush_all() Fastpath Local Privilege Escalation
CVE-2018-17182locallinux26 sep 2018
An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles
23RIESGO
abrir
Exploit-DBVexDay Proof
Super Cms Blog Pro 1.0 - SQL Injection
CVE-2018-17391webappsphp25 sep 2018
SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Article Factory Manager 4.3.9 - SQL Injection
CVE-2018-17380webappsphp25 sep 2018
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_e
23RIESGO
abrir
Exploit-DBVexDay Proof
Solaris - 'EXTREMEPARR' dtappgather Privilege Escalation (Metasploit)
CVE-2017-3622localsolaris25 sep 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (C
38RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGTextLayoutAttributes::context' Use-After-Free
CVE-2018-4318dosmultiple25 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::RenderLayer::updateDescendantDependentFlags' Use-After-Free
CVE-2018-4317dosmultiple25 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGTRefElement::updateReferencedText' Use-After-Free
CVE-2018-4315dosmultiple25 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Reverse Auction Factory 4.3.8 - SQL Injection
CVE-2018-17376webappsphp25 sep 2018
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::InlineTextBox::paint' Out-of-Bounds Read
CVE-2018-4328dosmultiple25 sep 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::Node::ensureRareData' Use-After-Free
CVE-2018-4306dosmultiple25 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Raffle Factory 3.5.2 - SQL Injection
CVE-2018-17379webappsphp25 sep 2018
SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order paramete
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::AXObjectCache::handleMenuItemSelected' Use-After-Free
CVE-2018-4312dosmultiple25 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Music Collection 3.0.3 - SQL Injection
CVE-2018-17375webappsphp25 sep 2018
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Penny Auction Factory 2.0.4 - SQL Injection
CVE-2018-17378webappsphp25 sep 2018
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order p
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Social Factory 3.8.3 - SQL Injection
CVE-2018-17385webappsphp25 sep 2018
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radiu
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Swap Factory 2.2.1 - SQL Injection
CVE-2018-17384webappsphp25 sep 2018
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component Jobs Factory 2.0.4 - SQL Injection
CVE-2018-17382webappsphp25 sep 2018
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - 'WebCore::SVGAnimateElementBase::resetAnimatedType' Use-After-Free
CVE-2018-4314dosmultiple25 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.