Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Joomla! Component Questions 1.4.3 - SQL Injection
CVE-2018-1737725 sep 2018
SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
23RIESGO
abrir
Exploit-DB
Joomla! Component Timetable Schedule 3.6.8 - SQL Injection
CVE-2018-1739425 sep 2018
SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
23RIESGO
abrir
Exploit-DB
Joomla! Component Social Factory 3.8.3 - SQL Injection
CVE-2018-1738525 sep 2018
SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radiu
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::AXObjectCache::handleMenuItemSelected' Use-After-Free
CVE-2018-431225 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::Node::ensureRareData' Use-After-Free
CVE-2018-430625 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DB
Joomla! Component Article Factory Manager 4.3.9 - SQL Injection
CVE-2018-1738025 sep 2018
SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_e
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::RenderLayer::updateDescendantDependentFlags' Use-After-Free
CVE-2018-431725 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::SVGTextLayoutAttributes::context' Use-After-Free
CVE-2018-431825 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DB
Joomla! Component Swap Factory 2.2.1 - SQL Injection
CVE-2018-1738425 sep 2018
SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
23RIESGO
abrir
Exploit-DB
Joomla! Component Music Collection 3.0.3 - SQL Injection
CVE-2018-1737525 sep 2018
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::SVGTRefElement::updateReferencedText' Use-After-Free
CVE-2018-431525 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DB
Joomla! Component Penny Auction Factory 2.0.4 - SQL Injection
CVE-2018-1737825 sep 2018
SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order p
23RIESGO
abrir
Exploit-DB
Joomla! Component Jobs Factory 2.0.4 - SQL Injection
CVE-2018-1738225 sep 2018
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RIESGO
abrir
Exploit-DB
Joomla! Component AlphaIndex Dictionaries 1.0 - SQL Injection
CVE-2018-1739725 sep 2018
SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::RenderTreeBuilder::removeAnonymousWrappersForInlineChildrenIfNeeded' Use-After-Free
CVE-2018-419725 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
23RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::SVGAnimateElementBase::resetAnimatedType' Use-After-Free
CVE-2018-431425 sep 2018
A use after free issue was addressed with improved memory management. This issue affected versions prior to iOS 12, tvOS
28RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::RenderMultiColumnSet::updateMinimumColumnHeight' Use-After-Free
CVE-2018-432325 sep 2018
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RIESGO
abrir
Exploit-DB
Joomla! Component CW Article Attachments 1.0.6 - 'id' SQL Injection
CVE-2018-1459224 sep 2018
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 fo
23RIESGO
abrir
Exploit-DB
MyBB Visual Editor 1.8.18 - Cross-Site Scripting
CVE-2018-1712824 sep 2018
A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
45RIESGO
abrir
Exploit-DB
LG SuperSign EZ CMS 2.5 - Remote Code Execution
CVE-2018-1717324 sep 2018
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RIESGO
abrir
Exploit-DB
WebRTC - VP9 Processing Use-After-Free
CVE-2018-1607121 sep 2018
A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap
23RIESGO
abrir
Exploit-DB
WebRTC - FEC Out-of-Bounds Read
CVE-2018-1608321 sep 2018
An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote
23RIESGO
abrir
Exploit-DB
WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion
CVE-2018-1628319 sep 2018
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RIESGO
abrir
Exploit-DB
Microsoft Windows - Double Dereference in NtEnumerateKey Elevation of Privilege
CVE-2018-841019 sep 2018
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'CiSetFileCache' WDAC Security Feature Bypass TOCTOU
CVE-2018-844919 sep 2018
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RIESGO
abrir
Exploit-DB
LG SuperSign EZ CMS 2.5 - Local File Inclusion
CVE-2018-1628819 sep 2018
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
50RIESGO
abrir
Exploit-DB
WordPress Plugin Localize My Post 1.0 - Local File Inclusion
CVE-2018-1629919 sep 2018
The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.
50RIESGO
abrir
Exploit-DB
Roundcube rcfilters plugin 2.1.6 - Cross-Site Scripting
CVE-2018-1673619 sep 2018
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters sec
23RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-100200018 sep 2018
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require ad
23RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-100200118 sep 2018
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.