Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DB
WordPress Plugin File Upload 4.3.2 - Stored Cross-Site Scripting
CVE-2018-9172webappsphp10 abr 2018
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
23RIESGO
abrir
Exploit-DB
Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control
CVE-2018-1217webappslinux10 abr 2018
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection A
50RIESGO
abrir
GitHub PoC14
Fixed No Virus Manual Automatic Loader exe no zip because zip picks up the anti virus detector.
CVE-2017-0213HIGHbajo ataqueransomware10 abr 2018
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
Exploit-DB
Cobub Razor 0.7.2 - Add New Superuser Account
CVE-2018-7745webappsphp09 abr 2018
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/inst
28RIESGO
abrir
Exploit-DB
WolfCMS 0.8.3.1 - Open Redirection
CVE-2018-8813webappsphp09 abr 2018
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attack
23RIESGO
abrir
Exploit-DB
WolfCMS 0.8.3.1 - Cross-Site Request Forgery
CVE-2018-8814webappsphp09 abr 2018
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication
23RIESGO
abrir
Exploit-DB
WordPress Plugin Background Takeover < 4.1.4 - Directory Traversal
CVE-2018-9118webappsphp09 abr 2018
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct
50RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - WebAssembly Parsing Does not Correctly Check Section Order
CVE-2018-4121dosmultiple09 abr 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RIESGO
abrir
Metasploit600
H2 Web Interface Create Alias RCE
CVE-2018-1005409 abr 2018
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can
30RIESGO
abrir
Exploit-DB
iScripts SonicBB 1.0 - Reflected Cross-Site Scripting (PoC)
CVE-2018-9235webappsphp09 abr 2018
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
23RIESGO
abrir
Exploit-DB
Yahei PHP Prober 0.4.7 - Cross-Site Scripting
CVE-2018-9238webappsphp09 abr 2018
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
23RIESGO
abrir
Exploit-DB
CyberArk Password Vault Web Access < 9.9.5 / < 9.10 / 10.1 - Remote Code Execution
CVE-2018-9843webappsjson09 abr 2018
The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute
28RIESGO
abrir
Exploit-DB
CyberArk Password Vault < 9.7 / < 10 - Memory Disclosure
CVE-2018-9842doslinux09 abr 2018
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RIESGO
abrir
GitHub PoC5
CVE-2017-8570生成脚本(CVE-2017-0199另一种利用方式)
CVE-2017-8570HIGHbajo ataque08 abr 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8570HIGHbajo ataque08 abr 2018
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
Exploit-DB
GNU Beep 1.3 - 'HoleyBeep' Local Privilege Escalation
CVE-2018-0492locallinux06 abr 2018
Johnathan Nightingale beep through 1.3.4, if setuid, has a race condition that allows local privilege escalation.
23RIESGO
abrir
Exploit-DBVexDay Proof
Cobub Razor 0.7.2 - Cross-Site Request Forgery
CVE-2018-7746webappsphp06 abr 2018
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/chann
23RIESGO
abrir
Exploit-DB
DotNetNuke DNNarticle Module 11 - Directory Traversal
CVE-2018-9126webappswindows06 abr 2018
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and conseque
35RIESGO
abrir
GitHub PoC3
Android Blueborne RCE CVE-2017-0781
CVE-2017-078106 abr 2018
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
Exploit-DB
Adobe Flash < 28.0.0.161 - Use-After-Free
CVE-2018-4878HIGHbajo ataqueransomwareremotemultiple06 abr 2018
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
Exploit-DB
FiberHome VDSL2 Modem HG 150-UB - Authentication Bypass
CVE-2018-9248webappshardware06 abr 2018
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
28RIESGO
abrir
Exploit-DB
Sophos Endpoint Protection Control Panel 10.7 - Weak Password Encryption
CVE-2018-9233localwindows06 abr 2018
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Vir
23RIESGO
abrir
GitHub PoC2
Android Blueborne RCE CVE-2017-0781
CVE-2017-078106 abr 2018
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
Exploit-DB
LineageOS 14.1 Blueborne - Remote Code Execution
CVE-2017-0781remoteandroid06 abr 2018
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
Exploit-DB
Sophos Endpoint Protection 10.7 - Tamper-Protection Bypass
CVE-2018-4863localwindows06 abr 2018
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKE
23RIESGO
abrir
Exploit-DB
YzmCMS 3.6 - Cross-Site Scripting
CVE-2018-7653webappsphp05 abr 2018
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
38RIESGO
abrir
Exploit-DB
Joomla! Component JS Jobs 1.2.0 - Cross-Site Scripting
CVE-2018-9183webappsphp05 abr 2018
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.
23RIESGO
abrir
Exploit-DB
Z-Blog 1.5.1.1740 - Full Path Disclosure
CVE-2018-7737webappsphp05 abr 2018
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.ph
23RIESGO
abrir
Exploit-DB
GetSimple CMS 3.3.13 - Cross-Site Scripting
CVE-2018-9173webappsphp05 abr 2018
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows rem
23RIESGO
abrir
Exploit-DB
WordPress Plugin Activity Log 2.4.0 - Cross-Site Scripting
CVE-2018-8729webappsphp05 abr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RIESGO
abrir
anteriorpágina 911 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.