Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.596exploits catalogados
36.656CVEs con explotación pública
24.695probados en laboratorio
79.457 exploits
Exploit-DB
SwitchVPN for macOS 2.1012.03 - Privilege Escalation
CVE-2018-18860localmacos14 nov 2018
A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-
23RIESGO
abrir
Exploit-DB
ntpd 4.2.8p10 - Out-of-Bounds Read (PoC)
CVE-2018-7182locallinux14 nov 2018
The ctl_getitem method in ntpd in ntp-4.2.8p6 before 4.2.8p11 allows remote attackers to cause a denial of service (out-
28RIESGO
abrir
Metasploit600
Nagios XI Magpie_debug.php Root Remote Code Execution
CVE-2018-1571014 nov 2018
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RIESGO
abrir
Metasploit600
Nagios XI Magpie_debug.php Root Remote Code Execution
CVE-2018-1570814 nov 2018
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RIESGO
abrir
Metasploit400
Redis Replication Code Execution
CVE-2018-1121813 nov 2018
Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10,
40RIESGO
abrir
Exploit-DBVexDay Proof
Evince 3.24.0 - Command Injection
CVE-2017-1000083doslinux13 nov 2018
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir
Exploit-DB
xorg-x11-server < 1.20.1 - Local Privilege Escalation
CVE-2018-14665locallinux13 nov 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
50RIESGO
abrir
GitHub PoC
My first try to code my own LPE exploit.
CVE-2017-1117613 nov 2018
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Immunet < 6.2.0 / Cisco AMP For Endpoints 6.2.0 - Denial of Service
CVE-2018-15437MEDIUMdoswindows13 nov 2018
Cisco Immunet and Cisco AMP for Endpoints System Scan Denial of Service Vulnerability
33RIESGO
abrir
Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2018-18774webappsphp13 nov 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RIESGO
abrir
Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2018-18773webappsphp13 nov 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demo
23RIESGO
abrir
Exploit-DB
ClipperCMS 1.3.3 - Cross-Site Request Forgery (File Upload)
CVE-2018-19135webappsphp13 nov 2018
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
23RIESGO
abrir
Exploit-DB
CentOS Web Panel 0.9.8.740 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2018-18772webappsphp13 nov 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as dem
23RIESGO
abrir
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-19043webappsphp12 nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename)
23RIESGO
abrir
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-19040webappsphp12 nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir para
28RIESGO
abrir
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-19041webappsphp12 nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the
23RIESGO
abrir
Exploit-DB
WordPress Plugin Media File Manager 1.4.2 - Directory Traversal / Cross-Site Scripting
CVE-2018-19042webappsphp12 nov 2018
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the di
23RIESGO
abrir
GitHub PoC9
CVE-2016-4657 web-kit vulnerability for ios 9.3, nintendo switch browser vulnerability
CVE-2016-4657HIGHbajo ataque11 nov 2018
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir
VulnCheck XDB
client-side
CVE-2016-4657HIGHbajo ataque11 nov 2018
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RIESGO
abrir
GitHub PoC
Setup, exploit and patch for CVE-2009-4092 Simplog CSRF
CVE-2009-409210 nov 2018
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote atta
23RIESGO
abrir
GitHub PoC1
Wordpress plugin Site-Editor v1.1.1 LFI exploit
CVE-2018-742209 nov 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
GitHub PoC10
PHPMyAdmin v4.8.0 and v.4.8.1 LFI exploit
CVE-2018-1261309 nov 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-1261309 nov 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-742209 nov 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
GitHub PoC5
CMS Made Simple 2.2.7 RCE exploit
CVE-2018-1051709 nov 2018
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code ex
23RIESGO
abrir
GitHub PoC
来自:https://www.freebuf.com/articles/web/31700.html
CVE-2014-0160HIGHbajo ataque08 nov 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC3
beraphin/CVE-2018-6789
CVE-2018-6789CRITICALbajo ataqueransomware08 nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2014-0160HIGHbajo ataque08 nov 2018
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-6789CRITICALbajo ataqueransomware08 nov 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
Metasploit300
WordPress WP GDPR Compliance Plugin Privilege Escalation
CVE-2018-1920708 nov 2018
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to exe
60RIESGO
abrir
anteriorpágina 866 / 2649siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.