Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.697exploits catalogados
36.715CVEs con explotación pública
24.695probados en laboratorio
79.697 exploits
Exploit-DB
SugarCRM 6.5.26 - Cross-Site Scripting
CVE-2018-17784webappsphp12 oct 2018
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthentic
23RIESGO
abrir
Exploit-DB
Phoenix Contact WebVisit 2985725 - Authentication Bypass
CVE-2016-8371webappswindows12 oct 2018
The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism i
28RIESGO
abrir
Exploit-DB
Phoenix Contact WebVisit 2985725 - Authentication Bypass
CVE-2016-8380webappswindows12 oct 2018
The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server Management Studio 17.9 - '.xel' XML External Entity Injection
CVE-2018-8527localwindows11 oct 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server Management Studio 17.9 - '.xmla' XML External Entity Injection
CVE-2018-8532localwindows11 oct 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft SQL Server Management Studio 17.9 - XML External Entity Injection
CVE-2018-8533localwindows11 oct 2018
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious X
28RIESGO
abrir
Exploit-DBVexDay Proof
jQuery-File-Upload 9.22.0 - Arbitrary File Upload
CVE-2018-9206webappsphp11 oct 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir
Exploit-DB
Phoenix Contact WebVisit 6.40.00 - Password Disclosure
CVE-2016-8366webappshardware11 oct 2018
Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coinciden
23RIESGO
abrir
Metasploit300
Nuuo Central Management Server Authenticated Arbitrary File Download
CVE-2018-1793411 oct 2018
NUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be res
23RIESGO
abrir
Metasploit300
Nuuo Central Management Server User Session Token Bruteforce
CVE-2018-1788811 oct 2018
NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers
23RIESGO
abrir
Metasploit0
Nuuo Central Management Server Authenticated Arbitrary File Upload
CVE-2018-1793611 oct 2018
NUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite co
23RIESGO
abrir
Metasploit300
Nuuo Central Management Authenticated SQL Server SQLi
CVE-2018-1898211 oct 2018
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b
50RIESGO
abrir
Exploit-DB
Ektron CMS 9.20 SP2 - Improper Access Restrictions
CVE-2018-12596webappsaspx10 oct 2018
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote at
28RIESGO
abrir
Exploit-DB
MicroTik RouterOS < 6.43rc3 - Remote Root
CVE-2018-14847CRITICALbajo ataqueremotehardware10 oct 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Type Confusion
CVE-2018-8467doswindows09 oct 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Exploit-DBVexDay Proof
Delta Electronics Delta Industrial Automation COMMGR 1.08 - Stack Buffer Overflow (Metasploit)
CVE-2018-10594remotewindows09 oct 2018
Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPS
50RIESGO
abrir
Exploit-DBVexDay Proof
ghostscript - executeonly Bypass with errorhandler Setup
CVE-2018-17961locallinux09 oct 2018
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RIESGO
abrir
Metasploit0
Windows NtUserSetWindowFNID Win32k User Callback
CVE-2018-8453HIGHbajo ataqueransomware09 oct 2018
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Metasploit600
blueimp's jQuery (Arbitrary) File Upload
CVE-2018-920609 oct 2018
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'BailOutOnInvalidatedArrayHeadSegment' Check Bypass
CVE-2018-8466doswindows09 oct 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Metasploit400
WebEx Local Service Permissions Exploit
CVE-2018-15442HIGH09 oct 2018
Cisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
61RIESGO
abrir
Exploit-DB
Seqrite End Point Security 7.4 - Privilege Escalation
CVE-2018-17775localwindows09 oct 2018
Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local us
23RIESGO
abrir
Exploit-DBVexDay Proof
ifwatchd - Privilege Escalation (Metasploit)
CVE-2014-2533locallinux09 oct 2018
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arb
38RIESGO
abrir
Exploit-DBVexDay Proof
Unitrends UEB - HTTP API Remote Code Execution (Metasploit)
CVE-2017-12478remotelinux08 oct 2018
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir
VulnCheck XDB
local
CVE-2018-14634HIGHbajo ataque08 oct 2018
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with a
76RIESGO
abrir
Exploit-DBVexDay Proof
Zahir Enterprise Plus 6 - Stack Buffer Overflow (Metasploit)
CVE-2018-17408localwindows08 oct 2018
Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute a
43RIESGO
abrir
GitHub PoC
OpenSSH < 7.7 User Enumeration CVE-2018-15473 Exploit
CVE-2018-15473MEDIUM08 oct 2018
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Exploit-DBVexDay Proof
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
CVE-2018-17552remotephp08 oct 2018
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigat
60RIESGO
abrir
Exploit-DBVexDay Proof
Navigate CMS - (Unauthenticated) Remote Code Execution (Metasploit)
CVE-2018-17553remotephp08 oct 2018
An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs N
60RIESGO
abrir
Metasploit600
Imperva SecureSphere PWS Command Injection
CVE-2018-1666008 oct 2018
A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with
23RIESGO
abrir
anteriorpágina 876 / 2657siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.