Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.596exploits catalogados
36.656CVEs con explotación pública
24.695probados en laboratorio
79.596 exploits
Exploit-DB
Git Submodule - Arbitrary Code Execution
CVE-2018-17456locallinux16 oct 2018
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir
Exploit-DBVexDay Proof
Solaris - RSH Stack Clash Privilege Escalation (Metasploit)
CVE-2017-1000364localsolaris16 oct 2018
An issue was discovered in the size of the stack guard page on Linux, specifically a 4k stack guard page is not sufficie
38RIESGO
abrir
Exploit-DBVexDay Proof
Solaris - RSH Stack Clash Privilege Escalation (Metasploit)
CVE-2017-3631localsolaris16 oct 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir
Exploit-DBVexDay Proof
Solaris - RSH Stack Clash Privilege Escalation (Metasploit)
CVE-2017-3629localsolaris16 oct 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions t
38RIESGO
abrir
Exploit-DB
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
CVE-2018-18324webappsphp15 oct 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter
23RIESGO
abrir
Exploit-DB
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
CVE-2018-18322webappsphp15 oct 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/ind
28RIESGO
abrir
Exploit-DB
NoMachine < 5.3.27 - Remote Code Execution
CVE-2018-17980remotewindows15 oct 2018
NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file lo
23RIESGO
abrir
Exploit-DB
Centos Web Panel 0.9.8.480 - Multiple Vulnerabilities
CVE-2018-18323webappsphp15 oct 2018
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-1650915 oct 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RIESGO
abrir
GitHub PoC61
PoC + Docker Environment for Python PIL/Pillow Remote Shell Command Execution via Ghostscript CVE-2018-16509
CVE-2018-1650915 oct 2018
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-14847CRITICALbajo ataque13 oct 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC15
Automated version of CVE-2018-14847 (MikroTik Exploit)
CVE-2018-14847CRITICALbajo ataque13 oct 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
Exploit-DB
SugarCRM 6.5.26 - Cross-Site Scripting
CVE-2018-17784webappsphp12 oct 2018
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic
23RIESGO
abrir
Exploit-DB
D-Link Routers - Plaintext Password
CVE-2018-10824webappshardware12 oct 2018
An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.
28RIESGO
abrir
Exploit-DB
Phoenix Contact WebVisit 2985725 - Authentication Bypass
CVE-2016-8380webappswindows12 oct 2018
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
28RIESGO
abrir
Exploit-DB
Phoenix Contact WebVisit 2985725 - Authentication Bypass
CVE-2016-8371webappswindows12 oct 2018
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism i
28RIESGO
abrir
Exploit-DB
D-Link Routers - Directory Traversal
CVE-2018-10822webappshardware12 oct 2018
Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L t
50RIESGO
abrir
Exploit-DB
D-Link Routers - Command Injection
CVE-2018-10823webappshardware12 oct 2018
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02
60RIESGO
abrir
Metasploit0
Nuuo Central Management Server Authenticated Arbitrary File Upload
CVE-2018-1793611 oct 2018
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite co
23RIESGO
abrir
Metasploit300
Nuuo Central Management Authenticated SQL Server SQLi
CVE-2018-1898211 oct 2018
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b
50RIESGO
abrir
Metasploit300
Nuuo Central Management Server Authenticated Arbitrary File Download
CVE-2018-1793411 oct 2018
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be res
23RIESGO
abrir
Metasploit300
Nuuo Central Management Server User Session Token Bruteforce
CVE-2018-1788811 oct 2018
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server Management Studio 17.9 - '.xel' XML External Entity Injection
CVE-2018-8527localwindows11 oct 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server Management Studio 17.9 - '.xmla' XML External Entity Injection
CVE-2018-8532localwindows11 oct 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RIESGO
abrir
Exploit-DB
Phoenix Contact WebVisit 6.40.00 - Password Disclosure
CVE-2016-8366webappshardware11 oct 2018
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coinciden
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server Management Studio 17.9 - XML External Entity Injection
CVE-2018-8533localwindows11 oct 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious X
28RIESGO
abrir
Exploit-DBVexDay Proof
jQuery-File-Upload 9.22.0 - Arbitrary File Upload
CVE-2018-9206webappsphp11 oct 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir
Exploit-DB
MicroTik RouterOS < 6.43rc3 - Remote Root
CVE-2018-14847CRITICALbajo ataqueremotehardware10 oct 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
Exploit-DB
Ektron CMS 9.20 SP2 - Improper Access Restrictions
CVE-2018-12596webappsaspx10 oct 2018
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at
28RIESGO
abrir
Exploit-DBVexDay Proof
ghostscript - executeonly Bypass with errorhandler Setup
CVE-2018-17961locallinux09 oct 2018
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RIESGO
abrir
anteriorpágina 874 / 2654siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.