Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.845exploits catalogados
36.824CVEs con explotación pública
24.695probados en laboratorio
79.697 exploits
Exploit-DB
WordPress Plugin Localize My Post 1.0 - Local File Inclusion
CVE-2018-16299webappsphp19 sep 2018
The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.
50RIESGO
abrir
Exploit-DB
WordPress Plugin Wechat Broadcast 1.2.0 - Local File Inclusion
CVE-2018-16283webappsphp19 sep 2018
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
50RIESGO
abrir
Exploit-DB
Roundcube rcfilters plugin 2.1.6 - Cross-Site Scripting
CVE-2018-16736webappslinux19 sep 2018
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters sec
23RIESGO
abrir
Exploit-DB
LG SuperSign EZ CMS 2.5 - Local File Inclusion
CVE-2018-16288webappshardware19 sep 2018
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
50RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'CiSetFileCache' WDAC Security Feature Bypass TOCTOU
CVE-2018-8449doswindows19 sep 2018
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Double Dereference in NtEnumerateKey Elevation of Privilege
CVE-2018-8410doswindows19 sep 2018
An elevation of privilege vulnerability exists when the Windows Kernel API improperly handles registry objects in memory
23RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-1002001webappsphp18 sep 2018
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-1002007webappsphp18 sep 2018
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-1002009webappsphp18 sep 2018
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'PathTypeHandlerBase::SetAttributesHelper' Type Confusion
CVE-2018-8384doswindows18 sep 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - 'localeCompare' Type Confusion
CVE-2018-8355doswindows18 sep 2018
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-1002002webappsphp18 sep 2018
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-1002004webappsphp18 sep 2018
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-1002005webappsphp18 sep 2018
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:4
23RIESGO
abrir
Exploit-DBVexDay Proof
Solaris - libnspr NSPR_LOG_FILE Privilege Escalation (Metasploit)
CVE-2006-4842localsolaris18 sep 2018
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-1002008webappsphp18 sep 2018
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-1002006webappsphp18 sep 2018
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact
23RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-1002003webappsphp18 sep 2018
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RIESGO
abrir
Exploit-DB
WordPress Plugin Arigato Autoresponder and Newsletter 2.5 - Blind SQL Injection / Reflected Cross-Site Scripting
CVE-2018-1002000webappsphp18 sep 2018
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require ad
23RIESGO
abrir
Exploit-DB
CA Release Automation NiMi 6.5 - Remote Command Execution
CVE-2018-15691remotejava17 sep 2018
Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows atta
28RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component JCK Editor 6.4.4 - 'parent' SQL Injection
CVE-2018-17254webappsphp17 sep 2018
The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
60RIESGO
abrir
GitHub PoC
Exploit SLmail Buffer Overflow CVE-2003-0264
CVE-2003-026416 sep 2018
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO arg
60RIESGO
abrir
Exploit-DB
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit)
CVE-2018-10576webappslinux14 sep 2018
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentica
23RIESGO
abrir
Exploit-DB
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit)
CVE-2018-10577webappslinux14 sep 2018
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices w
23RIESGO
abrir
Exploit-DB
Watchguard AP100 AP102 AP200 1.2.9.15 - Remote Code Execution (Metasploit)
CVE-2018-10575webappslinux14 sep 2018
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentia
23RIESGO
abrir
GitHub PoC515
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
CVE-2017-10271HIGHbajo ataqueransomware13 sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
Apache Portals Pluto 3.0.0 - Remote Code Execution
CVE-2018-1306webappswindows13 sep 2018
The PortletV3AnnotatedDemo Multipart Portlet war file code provided in Apache Pluto version 3.0.0 could allow a remote a
35RIESGO
abrir
GitHub PoC515
Java反序列化漏洞利用工具V1.0 Java反序列化相关漏洞的检查工具,采用JDK 1.8+NetBeans8.2开发,软件运行必须安装JDK 1.8或者以上版本。 支持:weblogic xml反序列化漏洞 CVE-2017-10271/CNVD-C-2019-48814/CVE-2019-2725检查。
CVE-2019-2725HIGHbajo ataqueransomware13 sep 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
VulnCheck XDB
local
CVE-2016-7255HIGHbajo ataque13 sep 2018
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
GitHub PoC1
porting CVE-2016-7255 to x86 for educational purposes.
CVE-2016-7255HIGHbajo ataque13 sep 2018
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir
anteriorpágina 880 / 2657siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.