Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
Exploit-DBVexDay Proof
OpenEMR 5.0.1.3 - (Authenticated) Arbitrary File Actions
CVE-2018-15140webappslinux16 ago 2018
Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authent
28RIESGO
abrir
Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
CVE-2018-11509webappscgi15 ago 2018
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applicat
28RIESGO
abrir
Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
CVE-2018-11510webappscgi15 ago 2018
The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/
35RIESGO
abrir
Exploit-DB
JioFi 4G M2S 1.0.2 - Denial of Service (PoC)
CVE-2018-15181doshardware15 ago 2018
JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS paylo
23RIESGO
abrir
Exploit-DB
ASUSTOR ADM 3.1.0.RFQ3 - Remote Command Execution / SQL Injection
CVE-2018-11511webappscgi15 ago 2018
The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability
43RIESGO
abrir
GitHub PoC259
PoC for CVE-2018-15133 (Laravel unserialize vulnerability)
CVE-2018-15133HIGHbajo ataque14 ago 2018
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
Exploit-DB
cgit 1.2.1 - Directory Traversal (Metasploit)
CVE-2018-14912webappslinux14 ago 2018
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-15133HIGHbajo ataque14 ago 2018
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
Exploit-DBVexDay Proof
Oracle GlassFish Server Open Source Edition 4.1 - Path Traversal (Metasploit)
CVE-2017-1000028webappswindows14 ago 2018
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir
Exploit-DB
Cloudme 1.9 - Buffer Overflow (DEP) (Metasploit)
CVE-2018-6892remotewindows_x86-6414 ago 2018
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
Exploit-DB
Oracle Glassfish OSE 4.1 - Path Traversal (Metasploit)
CVE-2017-1000028webappslinux14 ago 2018
Oracle, GlassFish Server Open Source Edition 4.1 is vulnerable to both authenticated and unauthenticated Directory Trave
60RIESGO
abrir
GitHub PoC
kaisaryousuf/CVE-2018-8208
CVE-2018-820813 ago 2018
An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual regis
23RIESGO
abrir
Exploit-DB
PostgreSQL 9.4-0.5.3 - Privilege Escalation
CVE-2017-14798HIGHlocallinux13 ago 2018
local privilege escalation in SUSE postgresql init script
41RIESGO
abrir
Exploit-DBVexDay Proof
Android - Directory Traversal over USB via Injection in blkid Output
CVE-2018-9445localandroid13 ago 2018
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local
23RIESGO
abrir
Exploit-DBVexDay Proof
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
CVE-2018-1513MEDIUMwebappsmultiple13 ago 2018
IBM Sterling B2B Integrator Standard Edition 5.2.0 through 5.2.6 is vulnerable to cross-site scripting. This vulnerabili
33RIESGO
abrir
Exploit-DBVexDay Proof
IBM Sterling B2B Integrator 5.2.0.1/5.2.6.3 - Cross-Site Scripting
CVE-2018-1563MEDIUMwebappsmultiple13 ago 2018
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site
33RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Weblogic Server - Deserialization Remote Code Execution (Metasploit)
CVE-2018-2628CRITICALbajo ataqueremotewindows13 ago 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
Metasploit300
Pimcore Gather Credentials via SQL Injection
CVE-2018-1405813 ago 2018
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
43RIESGO
abrir
Exploit-DB
Zimbra 8.6.0_GA_1153 - Cross-Site Scripting
CVE-2016-3411webappsphp10 ago 2018
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration before 8.7.0 allows remote attackers to inject arbitrar
23RIESGO
abrir
Exploit-DB
MyBB Thank You/Like Plugin 3.0.0 - Cross-Site Scripting
CVE-2018-14888webappsphp10 ago 2018
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa
23RIESGO
abrir
Exploit-DB
reSIProcate 1.10.2 - Heap Overflow
CVE-2018-12584dosmultiple09 ago 2018
The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows rem
28RIESGO
abrir
Exploit-DB
Linux Kernel 4.14.7 (Ubuntu 16.04 / CentOS 7) - (KASLR & SMEP Bypass) Arbitrary File Read
CVE-2017-18344locallinux09 ago 2018
The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly
23RIESGO
abrir
Exploit-DB
osTicket 1.10.1 - Arbitrary File Upload
CVE-2017-15580webappswindows08 ago 2018
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly v
28RIESGO
abrir
GitHub PoC119
Implements the POP/MOV SS (CVE-2018-8897) vulnerability by leveraging SYSCALL to perform a local privilege escalation (LPE).
CVE-2018-889708 ago 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-4233HIGH08 ago 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RIESGO
abrir
GitHub PoC178
Exploit for CVE-2018-4233, a WebKit JIT optimization bug used during Pwn2Own 2018
CVE-2018-4233HIGH08 ago 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
68RIESGO
abrir
Metasploit600
PHP Laravel Framework token Unserialize Remote Command Execution
CVE-2018-15133HIGHbajo ataque07 ago 2018
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
Metasploit600
PHP Laravel Framework token Unserialize Remote Command Execution
CVE-2017-1689407 ago 2018
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RIESGO
abrir
Exploit-DB
Open-AudIT Community 2.2.6 - Cross-Site Scripting
CVE-2018-14493webappswindows06 ago 2018
Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inj
35RIESGO
abrir
Exploit-DB
Subrion CMS 4.2.1 - Cross-Site Scripting
CVE-2018-14840webappsphp06 ago 2018
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for exam
23RIESGO
abrir
anteriorpágina 888 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.