Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
79.980 exploits
Exploit-DB
Task Rabbit Clone 1.0 - 'id' SQL Injection
CVE-2018-6363webappsphp28 ene 2018
SQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware28 ene 2018
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
Artifex MuJS 1.0.2 - Integer Overflow
CVE-2018-5759dosmultiple28 ene 2018
jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows re
23RIESGO
abrir
Exploit-DB
Multilanguage Real Estate MLM Script 3.0 - 'srch' SQL Injection
CVE-2018-6364webappsphp28 ene 2018
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
23RIESGO
abrir
Exploit-DB
Buddy Zone 2.9.9 - SQL Injection
CVE-2018-6367webappsphp28 ene 2018
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parame
23RIESGO
abrir
Exploit-DB
BMC BladeLogic 8.3.00.64 - Remote Command Execution
CVE-2016-1543remotemultiple26 ene 2018
The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux a
60RIESGO
abrir
Exploit-DB
BMC BladeLogic 8.3.00.64 - Remote Command Execution
CVE-2016-1542remotemultiple26 ene 2018
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RIESGO
abrir
Exploit-DB
BMC BladeLogic 8.3.00.64 - Remote Command Execution
CVE-2016-5063remotemultiple26 ene 2018
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RIESGO
abrir
Exploit-DB
Dodocool DC38 N300 - Cross-site Request Forgery
CVE-2018-5720webappshardware26 ene 2018
An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A C
23RIESGO
abrir
Exploit-DB
Exodus Wallet (ElectronJS Framework) - Remote Code Execution
CVE-2018-1000006remotewindows25 ene 2018
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RIESGO
abrir
Metasploit0
Exodus Wallet (ElectronJS Framework) remote Code Execution
CVE-2018-100000625 ene 2018
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RIESGO
abrir
GitHub PoC39
The Demo for CVE-2018-1000006
CVE-2018-100000625 ene 2018
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RIESGO
abrir
Exploit-DB
RAVPower 2.000.056 - Root Remote Code Execution
CVE-2018-5997remotehardware24 ene 2018
An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a pa
28RIESGO
abrir
Exploit-DBVexDay Proof
Sync Breeze Enterprise 9.5.16 - 'Import Command' Buffer Overflow (Metasploit)
CVE-2017-7310localwindows24 ene 2018
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9
50RIESGO
abrir
GitHub PoC
CVE-2017-7269利用代码(rb文件)
CVE-2017-7269CRITICALbajo ataque24 ene 2018
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in
100RIESGO
abrir
Exploit-DB
Professional Local Directory Script 1.0 - SQL Injection
CVE-2018-5973webappsphp24 ene 2018
SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter,
28RIESGO
abrir
Exploit-DB
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Encryption Keys Disclosure
CVE-2017-9248CRITICALbajo ataquewebappsaspx24 ene 2018
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not
100RIESGO
abrir
Exploit-DB
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Arbitrary File Upload
CVE-2017-11357CRITICALbajo ataqueransomwarewebappsaspx24 ene 2018
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which a
100RIESGO
abrir
Exploit-DB
Oracle VirtualBox < 5.1.30 / < 5.2-rc1 - Guest to Host Escape
CVE-2018-2698localmultiple24 ene 2018
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RIESGO
abrir
Exploit-DBVexDay Proof
GoAhead Web Server 2.5 < 3.6.5 - HTTPd 'LD_PRELOAD' Arbitrary Module Load (Metasploit)
CVE-2017-17562HIGHbajo ataqueremotemultiple24 ene 2018
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
Exploit-DBVexDay Proof
Kaltura - Remote PHP Code Execution over Cookie (Metasploit)
CVE-2017-14143remotephp24 ene 2018
The getUserzoneCookie function in Kaltura before 13.2.0 uses a hardcoded cookie secret to validate cookie signatures, wh
60RIESGO
abrir
Exploit-DB
Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Arbitrary File Upload
CVE-2017-11317CRITICALbajo ataquewebappsaspx24 ene 2018
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir
GitHub PoC20
BMC Bladelogic RSCD exploits including remote code execution - CVE-2016-1542, CVE-2016-1543, CVE-2016-5063
CVE-2016-154224 ene 2018
The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and U
60RIESGO
abrir
Exploit-DB
Zechat 1.5 - SQL Injection
CVE-2018-5978webappsphp23 ene 2018
SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
23RIESGO
abrir
Exploit-DB
Affiligator 2.1.0 - SQL Injection
CVE-2018-5977webappsphp23 ene 2018
SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= r
23RIESGO
abrir
Exploit-DB
Flexible Poll 1.2 - SQL Injection
CVE-2018-5988webappsphp23 ene 2018
SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.
28RIESGO
abrir
Exploit-DB
Tumder 2.1 - SQL Injection
CVE-2018-5984webappsphp23 ene 2018
SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the categor
23RIESGO
abrir
Exploit-DB
Photography CMS 1.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-5969webappsphp23 ene 2018
Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demons
23RIESGO
abrir
Exploit-DB
Quickad 4.0 - SQL Injection
CVE-2018-5972webappsphp23 ene 2018
SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listin
28RIESGO
abrir
Exploit-DB
LiveCRM SaaS Cloud 1.0 - SQL Injection
CVE-2018-5985webappsphp23 ene 2018
SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.
28RIESGO
abrir
anteriorpágina 925 / 2666siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.