Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
GitHub PoC
cve-2018-16283
CVE-2018-1628315 mar 2019
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RIESGO
abrir
Exploit-DB
Moodle 3.4.1 - Remote Code Execution
CVE-2018-1133webappsphp15 mar 2019
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RIESGO
abrir
GitHub PoC
The exploit python script for CVE-2018-7600
CVE-2018-7600CRITICALbajo ataqueransomware15 mar 2019
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities
CVE-2014-10078webappsphp15 mar 2019
Vembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfa
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware15 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC10
Noodle [Moodle RCE] (v3.4.1) - CVE-2018-1133
CVE-2018-113315 mar 2019
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code exec
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware15 mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC
cve-2019-9184
CVE-2019-918415 mar 2019
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir
GitHub PoC1
原创作者:Bearcat@secfree.com
CVE-2017-10271HIGHbajo ataqueransomware15 mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
Vembu Storegrid Web Interface 4.4.0 - Multiple Vulnerabilities
CVE-2014-10079webappsphp15 mar 2019
In Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hid
23RIESGO
abrir
Exploit-DB
FTPGetter Standard 5.97.0.177 - Remote Code Execution
CVE-2019-9760remotewindows14 mar 2019
FTPGetter Standard v.5.97.0.177 allows remote code execution when a user initiates an FTP connection to an attacker-cont
50RIESGO
abrir
Exploit-DB
WordPress Plugin GraceMedia Media Player 1.0 - Local File Inclusion
CVE-2019-9618webappsphp13 mar 2019
The GraceMedia Media Player plugin 1.0 for WordPress allows Local File Inclusion via the "cfg" parameter.
50RIESGO
abrir
Exploit-DB
pfSense 2.4.4-p1 (HAProxy Package 0.59_14) - Persistent Cross-Site Scripting
CVE-2019-8953webappsphp13 mar 2019
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, re
35RIESGO
abrir
Exploit-DBVexDay Proof
elFinder PHP Connector < 2.1.48 - 'exiftran' Command Injection (Metasploit)
CVE-2019-9194remotephp13 mar 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
Metasploit600
Ruby On Rails DoubleTap Development Mode secret_key_base Vulnerability
CVE-2019-542013 mar 2019
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir
Metasploit600
Zimbra Collaboration Autodiscover Servlet XXE and ProxyServlet SSRF
CVE-2019-9670CRITICALbajo ataque13 mar 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir
Metasploit600
Zimbra Collaboration Autodiscover Servlet XXE and ProxyServlet SSRF
CVE-2019-9621HIGHbajo ataque13 mar 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tika-server < 1.18 - Command Injection
CVE-2018-1335remotewindows13 mar 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Exploit-DB
Microsoft Windows MSHTML Engine - 'Edit' Remote Code Execution
CVE-2019-0541HIGHbajo ataquelocalwindows13 mar 2019
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML E
83RIESGO
abrir
Metasploit300
Microsoft Windows NtUserMNDragOver Local Privilege Elevation
CVE-2019-0808HIGHbajo ataque12 mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RIESGO
abrir
GitHub PoC
Bits generated while analyzing CVE-2019-6340 Drupal RESTful RCE
CVE-2019-6340HIGHbajo ataque12 mar 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC
AeolusTF/CVE-2018-20250
CVE-2018-20250HIGHbajo ataqueransomware11 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
Exploit-DB
PRTG Network Monitor 18.2.38 - (Authenticated) Remote Code Execution
CVE-2018-9276HIGHbajo ataquewebappswindows11 mar 2019
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir
Exploit-DB
Flexpaper PHP Publish Service 2.3.6 - Remote Code Execution
CVE-2018-11686webappsphp11 mar 2019
The Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_c
50RIESGO
abrir
Exploit-DB
Linux Kernel 4.4 (Ubuntu 16.04) - 'snd_timer_user_ccallback()' Kernel Pointer Leak
CVE-2016-4578doslinux11 mar 2019
sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local us
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-19276CRITICAL11 mar 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RIESGO
abrir
Metasploit300
CMS Made Simple (CMSMS) Showtime2 File Upload RCE
CVE-2019-969211 mar 2019
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware11 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
Metasploit300
Pimcore Unserialize RCE
CVE-2019-1086711 mar 2019
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RIESGO
abrir
GitHub PoC16
CVE-2018-19276 - OpenMRS Insecure Object Deserialization RCE
CVE-2018-19276CRITICAL11 mar 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RIESGO
abrir
anteriorpágina 847 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.