Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Cobub Razor 0.8.0 - SQL injection
CVE-2018-805716 abr 2018
A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a
28RIESGO
abrir
Exploit-DB
Microsoft Windows - 'nt!NtQueryFullAttributesFile' Kernel Stack Memory Disclosure
CVE-2018-097516 abr 2018
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Exploit-DB
AMD Plays.tv 1.27.5.0 - 'plays_service.exe' Arbitrary File Execution
CVE-2018-654615 abr 2018
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming
28RIESGO
abrir
Exploit-DB
MikroTik 6.41.4 - FTP daemon Denial of Service (PoC)
CVE-2018-1007013 abr 2018
A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU a
28RIESGO
abrir
Exploit-DB
Drupal < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution (PoC)
CVE-2018-7600CRITICALbajo ataqueransomware13 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
Drupal < 7.58 / < 8.3.9 / < 8.4.6 / < 8.5.1 - 'Drupalgeddon2' Remote Code Execution
CVE-2018-7600CRITICALbajo ataqueransomware13 abr 2018
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
Exploit-DB
Microsoft Credential Security Support Provider - Remote Code Execution
CVE-2018-088613 abr 2018
The Credential Security Support Provider protocol (CredSSP) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 S
45RIESGO
abrir
Exploit-DB
Joomla! Convert Forms version 2.0.3 - Formula Injection (CSV Injection)
CVE-2018-1006312 abr 2018
The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that
23RIESGO
abrir
Exploit-DB
DVD X Player Standard 5.5.3.9 - Buffer Overflow
CVE-2018-912810 abr 2018
DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.
23RIESGO
abrir
Exploit-DB
WUZHI CMS 4.1.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-992610 abr 2018
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=
23RIESGO
abrir
Exploit-DB
WordPress Plugin File Upload 4.3.2 - Stored Cross-Site Scripting
CVE-2018-917210 abr 2018
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
23RIESGO
abrir
Exploit-DB
WordPress Plugin Activity Log 2.4.0 - Stored Cross-Site Scripting
CVE-2018-872910 abr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RIESGO
abrir
Exploit-DB
Dell EMC Avamar and Integrated Data Protection Appliance Installation Manager - Invalid Access Control
CVE-2018-121710 abr 2018
Avamar Installation Manager in Dell EMC Avamar Server 7.3.1, 7.4.1, and 7.5.0, and Dell EMC Integrated Data Protection A
50RIESGO
abrir
Exploit-DB
WordPress Plugin File Upload 4.3.3 - Stored Cross-Site Scripting (PoC)
CVE-2018-984410 abr 2018
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
23RIESGO
abrir
Exploit-DB
iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
CVE-2018-923710 abr 2018
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
23RIESGO
abrir
Exploit-DB
iScripts Easycreate 3.2.1 - Stored Cross-Site Scripting
CVE-2018-923610 abr 2018
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
23RIESGO
abrir
Exploit-DB
Yahei PHP Prober 0.4.7 - Cross-Site Scripting
CVE-2018-923809 abr 2018
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
23RIESGO
abrir
Exploit-DB
iScripts SonicBB 1.0 - Reflected Cross-Site Scripting (PoC)
CVE-2018-923509 abr 2018
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
23RIESGO
abrir
Exploit-DB
WebKit - WebAssembly Parsing Does not Correctly Check Section Order
CVE-2018-412109 abr 2018
An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud b
28RIESGO
abrir
Exploit-DB
CyberArk Password Vault < 9.7 / < 10 - Memory Disclosure
CVE-2018-984209 abr 2018
CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replay
28RIESGO
abrir
Exploit-DB
WolfCMS 0.8.3.1 - Open Redirection
CVE-2018-881309 abr 2018
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attack
23RIESGO
abrir
Exploit-DB
CyberArk Password Vault Web Access < 9.9.5 / < 9.10 / 10.1 - Remote Code Execution
CVE-2018-984309 abr 2018
The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute
28RIESGO
abrir
Exploit-DB
Cobub Razor 0.7.2 - Add New Superuser Account
CVE-2018-774509 abr 2018
An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/install/inst
28RIESGO
abrir
Exploit-DB
WordPress Plugin Background Takeover < 4.1.4 - Directory Traversal
CVE-2018-911809 abr 2018
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Direct
50RIESGO
abrir
Exploit-DB
WolfCMS 0.8.3.1 - Cross-Site Request Forgery
CVE-2018-881409 abr 2018
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication
23RIESGO
abrir
Exploit-DB
Sophos Endpoint Protection 10.7 - Tamper-Protection Bypass
CVE-2018-486306 abr 2018
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKE
23RIESGO
abrir
Exploit-DB
LineageOS 14.1 Blueborne - Remote Code Execution
CVE-2017-078106 abr 2018
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
Exploit-DB
DotNetNuke DNNarticle Module 11 - Directory Traversal
CVE-2018-912606 abr 2018
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and conseque
35RIESGO
abrir
Exploit-DB
FiberHome VDSL2 Modem HG 150-UB - Authentication Bypass
CVE-2018-924806 abr 2018
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
28RIESGO
abrir
Exploit-DB
Sophos Endpoint Protection Control Panel 10.7 - Weak Password Encryption
CVE-2018-923306 abr 2018
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Vir
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.