Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.596exploits catalogados
36.656CVEs con explotación pública
24.695probados en laboratorio
79.596 exploits
Exploit-DB
PayPal-Credit Card-Debit Card Payment 1.0 - SQL Injection
CVE-2018-18800webappsphp29 oct 2018
The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=
23RIESGO
abrir
Exploit-DB
ASRock Drivers - Privilege Escalation
CVE-2018-10710doswindows29 oct 2018
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str
23RIESGO
abrir
Exploit-DB
Paramiko 2.4.1 - Authentication Bypass
CVE-2018-7750remotelinux29 oct 2018
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RIESGO
abrir
Exploit-DB
School Attendance Monitoring System 1.0 - Cross-Site Request Forgery (Update Admin)
CVE-2018-18797webappsphp29 oct 2018
School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
23RIESGO
abrir
Exploit-DB
School Event Management System 1.0 - Arbitrary File Upload
CVE-2018-18793webappsphp29 oct 2018
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RIESGO
abrir
Exploit-DB
K-iwi Framework 1775 - SQL Injection
CVE-2018-18755webappsphp29 oct 2018
K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/up
23RIESGO
abrir
Exploit-DB
Modbus Slave 7.0.0 - Denial of Service (PoC)
CVE-2018-18759doswindows29 oct 2018
Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow.
23RIESGO
abrir
Exploit-DB
School Attendance Monitoring System 1.0 - SQL Injection
CVE-2018-18798webappsphp29 oct 2018
Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.ph
23RIESGO
abrir
Exploit-DB
Bakeshop Inventory System in VB.Net and MS Access Database 1.0 - SQL Injection
CVE-2018-18804webappsphp29 oct 2018
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RIESGO
abrir
Exploit-DB
RhinOS CMS 3.x - Arbitrary File Download
CVE-2018-18760webappsphp29 oct 2018
RhinOS 3.0 build 1190 allows CSRF.
23RIESGO
abrir
Exploit-DB
School Attendance Monitoring System 1.0 - Arbitrary File Upload
CVE-2018-18799webappsphp29 oct 2018
School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
23RIESGO
abrir
Exploit-DB
ASRock Drivers - Privilege Escalation
CVE-2018-10711doswindows29 oct 2018
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str
23RIESGO
abrir
Exploit-DB
School Event Management System 1.0 - Cross-Site Request Forgery (Update Admin)
CVE-2018-18794webappsphp29 oct 2018
School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
23RIESGO
abrir
Exploit-DB
ASRock Drivers - Privilege Escalation
CVE-2018-10709doswindows29 oct 2018
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Str
23RIESGO
abrir
GitHub PoC4
Exploit for vulnerability CVE-2018-6389 on wordpress sites
CVE-2018-638928 oct 2018
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
VulnCheck XDB
local
CVE-2018-1466527 oct 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
GitHub PoC17
OpenBsd_CVE-2018-14665
CVE-2018-1466527 oct 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Exploit-DBVexDay Proof
WebEx - Local Service Permissions Exploit (Metasploit)
CVE-2018-15442HIGHlocalwindows25 oct 2018
Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61RIESGO
abrir
Exploit-DB
User Management 1.1 - Cross-Site Scripting
CVE-2018-18419webappsphp25 oct 2018
Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filen
23RIESGO
abrir
Exploit-DB
AjentiCP 1.2.23.13 - Cross-Site Scripting
CVE-2018-18548webappsphp25 oct 2018
ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in Fi
23RIESGO
abrir
Exploit-DB
xorg-x11-server < 1.20.3 - Local Privilege Escalation
CVE-2018-14665localmultiple25 oct 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Exploit-DB
ProjeQtOr Project Management Tool 7.2.5 - Remote Code Execution
CVE-2018-18924webappsphp25 oct 2018
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file
23RIESGO
abrir
Exploit-DB
Ekushey Project Manager CRM 3.1 - Cross-Site Scripting
CVE-2018-18417webappsphp25 oct 2018
In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as d
23RIESGO
abrir
Exploit-DB
Adult Filter 1.0 - Buffer Overflow (SEH)
CVE-2018-19459localwindows_x8625 oct 2018
Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file.
23RIESGO
abrir
Exploit-DBVexDay Proof
WebExec - (Authenticated) User Code Execution (Metasploit)
CVE-2018-15442HIGHremotewindows25 oct 2018
Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61RIESGO
abrir
Exploit-DB
Oracle Weblogic Server - Deserialization Remote Command Execution (Patch Bypass)
CVE-2018-2628CRITICALbajo ataqueremotemultiple25 oct 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
Exploit-DBVexDay Proof
libtiff 4.0.9 - Decodes Arbitrarily Sized JBIG into a Target Buffer
CVE-2018-18557doslinux25 oct 2018
LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3
28RIESGO
abrir
GitHub PoC
ensimag-security/CVE-2018-10933
CVE-2018-10933CRITICAL25 oct 2018
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
Metasploit400
Xorg X11 Server SUID modulepath Privilege Escalation
CVE-2018-1466525 oct 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Metasploit400
Xorg X11 Server SUID logfile Privilege Escalation
CVE-2018-1466525 oct 2018
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
anteriorpágina 871 / 2654siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.