Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Drupal avatar_uploader v7.x-1.0-beta8 - Arbitrary File Disclosure
CVE-2018-920523 abr 2018
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
50RIESGO
abrir
Exploit-DB
PRTG Network Monitor < 18.1.39.1648 - Stack Overflow (Denial of Service)
CVE-2018-1025323 abr 2018
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.
23RIESGO
abrir
Exploit-DB
Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
CVE-2017-1263523 abr 2018
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
Exploit-DB
Ncomputing vSpace Pro 10/11 - Directory Traversal
CVE-2018-1020123 abr 2018
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible t
50RIESGO
abrir
Exploit-DB
Oracle Weblogic Server 10.3.6.0 / 12.1.3.0 / 12.2.1.2 / 12.2.1.3 - Deserialization Remote Command Execution
CVE-2018-2628CRITICALbajo ataque22 abr 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
CVE-2018-877020 abr 2018
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, contro
50RIESGO
abrir
Exploit-DB
Cobub Razor 0.8.0 - Physical Path Leakage
CVE-2018-805620 abr 2018
Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/ma
28RIESGO
abrir
Exploit-DB
Lutron Quantum 2.0 - 3.2.243 - Information Disclosure
CVE-2018-888018 abr 2018
Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing th
28RIESGO
abrir
Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
CVE-2018-1007818 abr 2018
Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to i
23RIESGO
abrir
Exploit-DB
Easy File Sharing Web Server 7.2 - Stack Buffer Overflow
CVE-2018-905918 abr 2018
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code
60RIESGO
abrir
Exploit-DB
Match Clone Script 1.0.4 - Cross-Site Scripting
CVE-2018-985718 abr 2018
PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" sc
23RIESGO
abrir
Exploit-DB
Geist WatchDog Console 3.2.2 - Multiple Vulnerabilities
CVE-2018-1007718 abr 2018
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to re
23RIESGO
abrir
Exploit-DB
Kodi 17.6 - Persistent Cross-Site Scripting
CVE-2018-883118 abr 2018
A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/s
35RIESGO
abrir
Exploit-DB
WordPress Plugin Caldera Forms 1.5.9.1 - Cross-Site Scripting
CVE-2018-774718 abr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow re
23RIESGO
abrir
Exploit-DB
Brave Browser < 0.13.0 - 'window.close(self)' Denial of Service
CVE-2016-1071817 abr 2018
Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial
28RIESGO
abrir
Exploit-DB
Brave Browser < 0.13.0 - 'long alert() argument' Denial of Service
CVE-2017-1825617 abr 2018
Brave Browser before 0.13.0 allows remote attackers to cause a denial of service (resource consumption) via a long alert
23RIESGO
abrir
Exploit-DB
D-Link DIR-615 Wireless Router - Persistent Cross Site Scripting
CVE-2018-1011017 abr 2018
D-Link DIR-615 T1 devices allow XSS via the Add User feature.
23RIESGO
abrir
Exploit-DB
Ultra MiniHTTPd 1.2 - 'GET' Remote Stack Buffer Overflow (PoC)
CVE-2013-501917 abr 2018
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resour
50RIESGO
abrir
Exploit-DB
Joomla! Component jDownloads 3.2.58 - Cross Site Scripting
CVE-2018-1006817 abr 2018
The jDownloads extension before 3.2.59 for Joomla! has XSS.
23RIESGO
abrir
Exploit-DB
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (Metasploit)
CVE-2018-7600CRITICALbajo ataqueransomware17 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
Sophos Cyberoam UTM CR25iNG - 10.6.3 MR-5 - Direct Object Reference
CVE-2016-778616 abr 2018
Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via dir
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryVirtualMemory (MemoryImageInformation)' Kernel 64-bit Stack Memory Disclosure
CVE-2018-096816 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Exploit-DB
CloudMe Sync 1.11.0 - Local Buffer Overflow
CVE-2018-788616 abr 2018
An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" clie
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationTransactionManager (TransactionManagerRecoveryInformation)' Kernel Pool Memory Disclosure
CVE-2018-097216 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryInformationProcess (ProcessImageFileName)' Kernel 64-bit Pool/Stack Memory Disclosure
CVE-2018-097316 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQuerySystemInformation (SystemPageFileInformation(Ex))' Kernel 64-bit Stack Memory Disclosure
CVE-2018-097116 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Exploit-DB
Cobub Razor 0.8.0 - SQL injection
CVE-2018-805716 abr 2018
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a
28RIESGO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryVolumeInformationFile' Kernel Stack Memory Disclosure
CVE-2018-097016 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryVirtualMemory (Memory(Privileged)BasicInformation)' Kernel 64-bit Stack Memory Disclosure
CVE-2018-097416 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryAttributesFile' Kernel Stack Memory Disclosure
CVE-2018-096916 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.