Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
Exploit-DB
Sitecore.Net 8.1 - Directory Traversal
CVE-2018-7669webappsaspx06 ago 2018
An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application
28RIESGO
abrir
Exploit-DB
LAMS < 3.1 - Cross-Site Scripting
CVE-2018-12090webappsjava06 ago 2018
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introd
23RIESGO
abrir
Exploit-DBVexDay Proof
Fortinet FortiClient 5.2.3 (Windows 10 x64 Creators) - Local Privilege Escalation
CVE-2015-4077localwindows_x86-6405 ago 2018
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RIESGO
abrir
Exploit-DBVexDay Proof
Fortinet FortiClient 5.2.3 (Windows 10 x64 Creators) - Local Privilege Escalation
CVE-2015-5736localwindows_x86-6405 ago 2018
The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel
23RIESGO
abrir
Metasploit300
Windows unmarshal post exploitation
CVE-2018-0824HIGHbajo ataque05 ago 2018
A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized
100RIESGO
abrir
Metasploit600
NUUO NVRmini upgrade_handle.php Remote Command Execution
CVE-2018-14933CRITICALbajo ataque04 ago 2018
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RIESGO
abrir
GitHub PoC6
Foxit Reader version 9.0.1.1049 Use After Free with ASLR and DEP bypass on heap
CVE-2018-994804 ago 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
GitHub PoC61
CVE-2007-2447 - Samba usermap script
CVE-2007-244703 ago 2018
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel - UDP Fragmentation Offset 'UFO' Privilege Escalation (Metasploit)
CVE-2017-1000112locallinux03 ago 2018
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RIESGO
abrir
Exploit-DB
PHP Template Store Script 3.0.6 - Cross-Site Scripting
CVE-2018-14869webappsphp03 ago 2018
PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field i
23RIESGO
abrir
Exploit-DB
Vuze Bittorrent Client 5.7.6.0 - SSDP Processing XML External Entity Injection
CVE-2018-13417webappsxml03 ago 2018
In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External E
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-9248CRITICALbajo ataque03 ago 2018
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
GitHub PoC96
A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248.
CVE-2017-9248CRITICALbajo ataque03 ago 2018
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
Exploit-DB
Plex Media Server 1.13.2.5154 - SSDP Processing XML External Entity Injection
CVE-2018-13415webappsxml03 ago 2018
In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External En
35RIESGO
abrir
Metasploit300
cgit Directory Traversal
CVE-2018-1491203 ago 2018
cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned
60RIESGO
abrir
Exploit-DB
Seq 4.2.476 - Authentication Bypass
CVE-2018-8096webappswindows02 ago 2018
Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name
35RIESGO
abrir
Metasploit300
Mikrotik Winbox Arbitrary File Read
CVE-2018-14847CRITICALbajo ataque02 ago 2018
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
Exploit-DB
Sun Solaris 11.3 AVS Kernel - Local Privilege Escalation
CVE-2018-2892localsolaris02 ago 2018
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service).
23RIESGO
abrir
Exploit-DB
Universal Media Server 7.1.0 - SSDP Processing XML External Entity Injection
CVE-2018-13416webappsxml02 ago 2018
In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML Extern
28RIESGO
abrir
Exploit-DB
WityCMS 0.6.2 - Cross-Site Request Forgery (Password Change)
CVE-2018-14029webappsphp02 ago 2018
CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as dem
23RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALbajo ataque02 ago 2018
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RIESGO
abrir
GitHub PoC2
Crestron AirMedia AM-100 Traversal and Hashdump Metasploit Modules
CVE-2016-563901 ago 2018
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13
28RIESGO
abrir
Exploit-DB
Craft CMS SEOmatic plugin 3.1.4 - Server-Side Template Injection
CVE-2018-14716webappslinux31 jul 2018
A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because reques
35RIESGO
abrir
Exploit-DB
Responsive Filemanager 9.13.1 - Server-Side Request Forgery
CVE-2018-14728webappslinux30 jul 2018
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RIESGO
abrir
GitHub PoC20
on Mac 10.12.2
CVE-2017-237030 jul 2018
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RIESGO
abrir
Exploit-DB
Charles Proxy 4.2 - Local Privilege Escalation
CVE-2017-15358localmacos30 jul 2018
Race condition in the Charles Proxy Settings suid binary in Charles Proxy before 4.2.1 allows local users to gain privil
23RIESGO
abrir
Exploit-DB
H2 Database 1.4.197 - Information Disclosure
CVE-2018-14335MEDIUMwebappslinux30 jul 2018
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read
38RIESGO
abrir
Exploit-DBVexDay Proof
fusermount - user_allow_other Restriction Bypass and SELinux Label Control
CVE-2018-10906MEDIUMdoslinux30 jul 2018
In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is act
33RIESGO
abrir
VulnCheck XDB
client-side
CVE-2016-9079HIGHbajo ataque29 jul 2018
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
GitHub PoC7
A demo exploit of CVE-2016-9079 on Ubuntu x64
CVE-2016-9079HIGHbajo ataque29 jul 2018
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
anteriorpágina 889 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.