Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
CVE-2018-1832315 oct 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/
60RIESGO
abrir
Exploit-DB
NoMachine < 5.3.27 - Remote Code Execution
CVE-2018-1798015 oct 2018
NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file lo
23RIESGO
abrir
Exploit-DB
Phoenix Contact WebVisit 2985725 - Authentication Bypass
CVE-2016-837112 oct 2018
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism i
28RIESGO
abrir
Exploit-DB
SugarCRM 6.5.26 - Cross-Site Scripting
CVE-2018-1778412 oct 2018
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic
23RIESGO
abrir
Exploit-DB
D-Link Routers - Plaintext Password
CVE-2018-1082412 oct 2018
An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.
28RIESGO
abrir
Exploit-DB
D-Link Routers - Directory Traversal
CVE-2018-1082212 oct 2018
Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L t
50RIESGO
abrir
Exploit-DB
D-Link Routers - Command Injection
CVE-2018-1082312 oct 2018
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02
60RIESGO
abrir
Exploit-DB
Phoenix Contact WebVisit 2985725 - Authentication Bypass
CVE-2016-838012 oct 2018
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
28RIESGO
abrir
Exploit-DB
Microsoft SQL Server Management Studio 17.9 - '.xel' XML External Entity Injection
CVE-2018-852711 oct 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RIESGO
abrir
Exploit-DB
jQuery-File-Upload 9.22.0 - Arbitrary File Upload
CVE-2018-920611 oct 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir
Exploit-DB
Phoenix Contact WebVisit 6.40.00 - Password Disclosure
CVE-2016-836611 oct 2018
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coinciden
23RIESGO
abrir
Exploit-DB
Microsoft SQL Server Management Studio 17.9 - '.xmla' XML External Entity Injection
CVE-2018-853211 oct 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RIESGO
abrir
Exploit-DB
Microsoft SQL Server Management Studio 17.9 - XML External Entity Injection
CVE-2018-853311 oct 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious X
28RIESGO
abrir
Exploit-DB
Ektron CMS 9.20 SP2 - Improper Access Restrictions
CVE-2018-1259610 oct 2018
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at
28RIESGO
abrir
Exploit-DB
MicroTik RouterOS < 6.43rc3 - Remote Root
CVE-2018-14847CRITICALbajo ataque10 oct 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Type Confusion
CVE-2018-846709 oct 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Exploit-DB
ifwatchd - Privilege Escalation (Metasploit)
CVE-2014-253309 oct 2018
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arb
38RIESGO
abrir
Exploit-DB
ghostscript - executeonly Bypass with errorhandler Setup
CVE-2018-1796109 oct 2018
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RIESGO
abrir
Exploit-DB
Delta Electronics Delta Industrial Automation COMMGR 1.08 - Stack Buffer Overflow (Metasploit)
CVE-2018-1059409 oct 2018
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPS
50RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - 'BailOutOnInvalidatedArrayHeadSegment' Check Bypass
CVE-2018-846609 oct 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Exploit-DB
Seqrite End Point Security 7.4 - Privilege Escalation
CVE-2018-1777509 oct 2018
Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local us
23RIESGO
abrir
Exploit-DB
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
CVE-2018-1755208 oct 2018
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigat
60RIESGO
abrir
Exploit-DB
Zahir Enterprise Plus 6 - Stack Buffer Overflow (Metasploit)
CVE-2018-1740808 oct 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RIESGO
abrir
Exploit-DB
Unitrends UEB - HTTP API Remote Code Execution (Metasploit)
CVE-2018-632808 oct 2018
It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, w
50RIESGO
abrir
Exploit-DB
net-snmp 5.7.3 - (Authenticated) Denial of Service (PoC)
CVE-2015-5621HIGH08 oct 2018
The snmp_pdu_parse function in snmp_api.c in net-snmp 5.7.2 and earlier does not remove the varBind variable in a netsnm
53RIESGO
abrir
Exploit-DB
Microsoft Windows - Net-NTLMv2 Reflection DCOM/RPC (Metasploit)
CVE-2016-322508 oct 2018
The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
50RIESGO
abrir
Exploit-DB
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
CVE-2018-1755308 oct 2018
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RIESGO
abrir
Exploit-DB
Unitrends UEB - HTTP API Remote Code Execution (Metasploit)
CVE-2017-1247808 oct 2018
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir
Exploit-DB
net-snmp 5.7.3 - (Authenticated) Denial of Service (PoC)
CVE-2018-1806508 oct 2018
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by
28RIESGO
abrir
Exploit-DB
Git Submodule - Arbitrary Code Execution (PoC)
CVE-2018-1745605 oct 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.