Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.900exploits catalogados
36.847CVEs con explotación pública
24.695probados en laboratorio
79.900 exploits
Exploit-DBVexDay Proof
Skia - Heap Overflow in SkScan::FillPath due to Precision Error
CVE-2018-6126dosmultiple27 jul 2018
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m
23RIESGO
abrir
Exploit-DBVexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-10661remotelinux27 jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RIESGO
abrir
Exploit-DB
Online Trade 1 - Information Disclosure
CVE-2018-14328webappslinux27 jul 2018
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RIESGO
abrir
Exploit-DBVexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-10662remotelinux27 jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RIESGO
abrir
Exploit-DBVexDay Proof
SoftNAS Cloud < 4.0.3 - OS Command Injection
CVE-2018-14417webappsphp27 jul 2018
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RIESGO
abrir
Exploit-DBVexDay Proof
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-10660remotelinux27 jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-289326 jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RIESGO
abrir
Exploit-DB
Trivum Multiroom Setup Tool 8.76 - Corss-Site Request Forgery (Admin Bypass)
CVE-2018-13859webappshardware26 jul 2018
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, all
28RIESGO
abrir
Metasploit600
Network Manager VPNC Username Privilege Escalation
CVE-2018-10900HIGH26 jul 2018
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac
56RIESGO
abrir
Exploit-DB
GetGo Download Manager 6.2.1.3200 - Denial of Service (PoC)
CVE-2017-17849doswindows25 jul 2018
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RIESGO
abrir
GitHub PoC
PercussiveElbow/CVE-2004-2271-MiniShare-1.4.1-Buffer-Overflow
CVE-2004-227125 jul 2018
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET req
60RIESGO
abrir
Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
CVE-2018-12465CRITICALwebappsphp24 jul 2018
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RIESGO
abrir
Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
CVE-2018-12464CRITICALwebappsphp24 jul 2018
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RIESGO
abrir
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-13457doslinux24 jul 2018
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RIESGO
abrir
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-13441doslinux24 jul 2018
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows atta
23RIESGO
abrir
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-13458doslinux24 jul 2018
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RIESGO
abrir
GitHub PoC8
CVE-2013-6117
CVE-2013-611723 jul 2018
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RIESGO
abrir
Exploit-DB
Davolink DVW 3200 Router - Password Disclosure
CVE-2018-10618webappshardware23 jul 2018
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke
28RIESGO
abrir
Exploit-DB
Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
CVE-2015-5996webappshardware23 jul 2018
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allo
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2013-611723 jul 2018
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive informatio
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-289322 jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
60RIESGO
abrir
Exploit-DB
Inteno’s IOPSYS - (Authenticated) Local Privilege Escalation
CVE-2018-14533locallinux21 jul 2018
read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /v
23RIESGO
abrir
GitHub PoC2
This Python 3 script is for uploading shell (and other files) to Windows Server / Linux via Oracle 11g R2 (CVE-2010-3600).
CVE-2010-360020 jul 2018
Unspecified vulnerability in the Client System Analyzer component in Oracle Database Server 11.1.0.7 and 11.2.0.1 and En
60RIESGO
abrir
Exploit-DB
Touchpad / Trivum WebTouch Setup 2.53 build 13163 - Authentication Bypass
CVE-2018-13862webappshardware20 jul 2018
Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attacker
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-289420 jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Su
50RIESGO
abrir
Exploit-DB
MSVOD 10 - 'cid' SQL Injection
CVE-2018-14418webappsphp20 jul 2018
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
23RIESGO
abrir
Exploit-DB
TP-Link TL-WR840N - Denial of Service
CVE-2018-14336doshardware20 jul 2018
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-289419 jul 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Su
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux - BPF Sign Extension Local Privilege Escalation (Metasploit)
CVE-2017-16995locallinux19 jul 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
Exploit-DB
WordPress Plugin All In One Favicon 4.6 - (Authenticated) Cross-Site Scripting
CVE-2018-13832webappsphp19 jul 2018
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
23RIESGO
abrir
anteriorpágina 890 / 2664siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.