Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
DomainMOD 4.11.01 - 'raid' Cross-Site Scripting
CVE-2018-1913616 nov 2018
DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.
38RIESGO
abrir
Exploit-DB
PHP-Proxy 5.1.0 - Local File Inclusion
CVE-2018-1924615 nov 2018
PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users w
28RIESGO
abrir
Exploit-DB
WordPress Plugin Ninja Forms 3.3.17 - Cross-Site Scripting
CVE-2018-1928715 nov 2018
XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes
38RIESGO
abrir
Exploit-DB
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
CVE-2018-1576814 nov 2018
Insecure MySQL Configuration Vulnerability
23RIESGO
abrir
Exploit-DB
SwitchVPN for macOS 2.1012.03 - Privilege Escalation
CVE-2018-1886014 nov 2018
A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-
23RIESGO
abrir
Exploit-DB
Advanced Comment System 1.0 - SQL Injection
CVE-2018-1861914 nov 2018
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability bec
23RIESGO
abrir
Exploit-DB
ntpd 4.2.8p10 - Out-of-Bounds Read (PoC)
CVE-2018-718214 nov 2018
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-
28RIESGO
abrir
Exploit-DB
Dell OpenManage Network Manager 6.2.0.51 SP3 - Multiple Vulnerabilities
CVE-2018-1576714 nov 2018
Improper Authorization Vulnerability
28RIESGO
abrir
Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2018-1877313 nov 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demo
23RIESGO
abrir
Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2018-1877213 nov 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem
23RIESGO
abrir
Exploit-DB
ClipperCMS 1.3.3 - Cross-Site Request Forgery (File Upload)
CVE-2018-1913513 nov 2018
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
23RIESGO
abrir
Exploit-DB
Evince 3.24.0 - Command Injection
CVE-2017-100008313 nov 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir
Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2018-1877413 nov 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RIESGO
abrir
Exploit-DB
xorg-x11-server < 1.20.1 - Local Privilege Escalation
CVE-2018-1466513 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-1904012 nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir para
28RIESGO
abrir
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-1904312 nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename)
28RIESGO
abrir
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-1904212 nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di
28RIESGO
abrir
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-1904112 nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the
23RIESGO
abrir
Exploit-DB
OpenSLP 2.0.0 - Multiple Vulnerabilities
CVE-2016-756707 nov 2018
Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have
28RIESGO
abrir
Exploit-DB
blueimp's jQuery 9.22.0 - (Arbitrary) File Upload (Metasploit)
CVE-2018-920606 nov 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir
Exploit-DB
CMS Made Simple 2.2.7 - (Authenticated) Remote Code Execution
CVE-2018-1051706 nov 2018
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
28RIESGO
abrir
Exploit-DB
FaceTime - 'VCPDecompressionDecodeFrame' Memory Corruption
CVE-2018-436606 nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RIESGO
abrir
Exploit-DB
FaceTime - 'readSPSandGetDecoderParams' Stack Corruption
CVE-2018-436706 nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1.
23RIESGO
abrir
Exploit-DB
libiec61850 1.3 - Stack Based Buffer Overflow
CVE-2018-1895706 nov 2018
An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_pu
28RIESGO
abrir
Exploit-DB
FaceTime - RTP Video Processing Heap Corruption
CVE-2018-438406 nov 2018
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to iOS 12.1,
23RIESGO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-1885705 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-1885605 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir
Exploit-DB
Advantech WebAccess SCADA 8.3.2 - Remote Code Execution
CVE-2018-1570705 nov 2018
Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could
23RIESGO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-1885805 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir
Exploit-DB
LiquidVPN 1.36 / 1.37 - Privilege Escalation
CVE-2018-1885905 nov 2018
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.