Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-575412 jun 2018
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-575212 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-575612 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-575112 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2018-575512 jun 2018
Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.
23RIESGO
abrir
Exploit-DB
OX App Suite 7.8.4 - Multiple Vulnerabilities
CVE-2017-1706212 jun 2018
The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir
Exploit-DB
Canon PrintMe EFI - Cross-Site Scripting
CVE-2018-1211112 jun 2018
Cross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DB
WebKitGTK+ < 2.21.3 - 'WebKitFaviconDatabase' Denial of Service (Metasploit)
CVE-2018-1164611 jun 2018
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFavicon
50RIESGO
abrir
Exploit-DB
Schools Alert Management Script - 'get_sec.php' SQL Injection
CVE-2018-1205211 jun 2018
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
23RIESGO
abrir
Exploit-DB
Schools Alert Management Script - SQL Injection
CVE-2018-1205511 jun 2018
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.ph
23RIESGO
abrir
Exploit-DB
Schools Alert Management Script - Arbitrary File Read
CVE-2018-1205411 jun 2018
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absol
50RIESGO
abrir
Exploit-DB
WordPress Plugin Pie Register < 3.0.9 - Blind SQL Injection
CVE-2018-1096911 jun 2018
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute ar
23RIESGO
abrir
Exploit-DB
Schools Alert Management Script - Arbitrary File Deletion
CVE-2018-1205311 jun 2018
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.p
28RIESGO
abrir
Exploit-DB
WebKit - WebAssembly Compilation Info Leak
CVE-2018-422208 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
28RIESGO
abrir
Exploit-DB
WebRTC - VP9 Missing Frame Processing Out-of-Bounds Memory Access
CVE-2018-612908 jun 2018
Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially per
23RIESGO
abrir
Exploit-DB
Google Chrome - Integer Overflow when Processing WebAssembly Locals
CVE-2018-609208 jun 2018
An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker t
23RIESGO
abrir
Exploit-DB
XiongMai uc-httpd 1.0.0 - Buffer Overflow
CVE-2018-1008808 jun 2018
Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE
50RIESGO
abrir
Exploit-DB
TrendMicro OfficeScan XG 11.0 - Change Prevention Bypass
CVE-2018-1050708 jun 2018
A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or
23RIESGO
abrir
Exploit-DB
Splunk < 7.0.1 - Information Disclosure
CVE-2018-1140908 jun 2018
Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json
60RIESGO
abrir
Exploit-DB
WebKit - Use-After-Free when Resuming Generator
CVE-2018-421808 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud
23RIESGO
abrir
Exploit-DB
WebRTC - VP9 Frame Processing Out-of-Bounds Memory Access
CVE-2018-613008 jun 2018
Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to pot
23RIESGO
abrir
Exploit-DB
Monstra CMS < 3.0.4 - Cross-Site Scripting (1)
CVE-2018-1011807 jun 2018
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RIESGO
abrir
Exploit-DB
PHP 7.2.2 - 'php_stream_url_wrap_http_ex' Buffer Overflow
CVE-2018-758406 jun 2018
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer
45RIESGO
abrir
Exploit-DB
Apple macOS Kernel - Use-After-Free Due to Lack of Locking in nvidia GeForce Driver
CVE-2018-423006 jun 2018
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Grap
23RIESGO
abrir
Exploit-DB
XNU Kernel - Heap Overflow Due to Bad Bounds Checking in MPTCP
CVE-2018-424106 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RIESGO
abrir
Exploit-DB
Apple macOS/iOS Kernel - Heap Overflow Due to Lack of Lower Size Check in getvolattrlist
CVE-2018-424306 jun 2018
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
28RIESGO
abrir
Exploit-DB
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4655MEDIUMbajo ataque05 jun 2018
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir
Exploit-DB
WebKit - not_number defineProperties UAF (Metasploit)
CVE-2016-4656HIGHbajo ataque05 jun 2018
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RIESGO
abrir
Exploit-DB
Linux Kernel < 4.16.11 - 'ext4_read_inline_data()' Memory Corruption
CVE-2018-1141205 jun 2018
In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untruste
28RIESGO
abrir
Exploit-DB
Jenkins Mailer Plugin < 1.20 - Cross-Site Request Forgery (Send Email)
CVE-2018-871805 jun 2018
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.