Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Sophos Endpoint Protection 10.7 - Tamper-Protection Bypass
CVE-2018-486306 abr 2018
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKE
23RIESGO
abrir
Exploit-DB
DotNetNuke DNNarticle Module 11 - Directory Traversal
CVE-2018-912606 abr 2018
The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and conseque
35RIESGO
abrir
Exploit-DB
LineageOS 14.1 Blueborne - Remote Code Execution
CVE-2017-078106 abr 2018
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
Exploit-DB
Z-Blog 1.5.1.1740 - Cross-Site Scripting
CVE-2018-773605 abr 2018
In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the so
23RIESGO
abrir
Exploit-DB
Microsoft Windows Defender - 'mpengine.dll' Memory Corruption
CVE-2018-098605 abr 2018
A remote code execution vulnerability exists when the Microsoft Malware Protection Engine does not properly scan a speci
35RIESGO
abrir
Exploit-DB
Microsoft Windows - Multiple Use-After-Free Issues in jscript Array Methods
CVE-2018-093505 abr 2018
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RIESGO
abrir
Exploit-DB
WebRTC - Private IP Leakage (Metasploit)
CVE-2018-684905 abr 2018
In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client informati
50RIESGO
abrir
Exploit-DB
Z-Blog 1.5.1.1740 - Full Path Disclosure
CVE-2018-773705 abr 2018
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.ph
23RIESGO
abrir
Exploit-DB
WordPress Plugin Activity Log 2.4.0 - Cross-Site Scripting
CVE-2018-872905 abr 2018
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RIESGO
abrir
Exploit-DB
YzmCMS 3.6 - Cross-Site Scripting
CVE-2018-765305 abr 2018
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
38RIESGO
abrir
Exploit-DB
GetSimple CMS 3.3.13 - Cross-Site Scripting
CVE-2018-917305 abr 2018
Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows rem
23RIESGO
abrir
Exploit-DB
Joomla! Component JS Jobs 1.2.0 - Cross-Site Scripting
CVE-2018-918305 abr 2018
The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.
23RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (1)
CVE-2018-093303 abr 2018
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (2)
CVE-2018-093403 abr 2018
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RIESGO
abrir
Exploit-DB
Microsoft Edge Chakra JIT - Stack-to-Heap Copy (Incomplete Fix) (1)
CVE-2018-093403 abr 2018
ChakraCore and Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution,
35RIESGO
abrir
Exploit-DB
Google Chrome V8 - 'ElementsAccessorBase::CollectValuesOrEntriesImpl' Type Confusion
CVE-2018-606403 abr 2018
Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote
23RIESGO
abrir
Exploit-DB
Frog CMS 0.9.5 - Cross-Site Request Forgery (Add User)
CVE-2018-890802 abr 2018
An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CS
23RIESGO
abrir
Exploit-DB
OpenCMS 10.5.3 - Cross-Site Scripting
CVE-2018-881502 abr 2018
Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to in
23RIESGO
abrir
Exploit-DB
WampServer 3.1.2 - Cross-Site Request Forgery
CVE-2018-881702 abr 2018
Wampserver before 3.1.3 has CSRF in add_vhost.php.
23RIESGO
abrir
Exploit-DB
OpenCMS 10.5.3 - Cross-Site Request Forgery
CVE-2018-881102 abr 2018
Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allow
23RIESGO
abrir
Exploit-DB
WampServer 3.1.1 - Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-873202 abr 2018
Cross-site scripting (XSS) vulnerability in WampServer 3.1.1 allows remote attackers to inject arbitrary web script or H
23RIESGO
abrir
Exploit-DB
DLink DIR-601 - Admin Password Disclosure
CVE-2018-570802 abr 2018
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticat
23RIESGO
abrir
Exploit-DB
Open-AuditIT Professional 2.1 - Cross-Site Request Forgery
CVE-2018-897930 mar 2018
Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the cre
23RIESGO
abrir
Exploit-DB
Joomla! Component Acymailing Starter 5.9.5 - CSV Macro Injection
CVE-2018-910730 mar 2018
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing exte
23RIESGO
abrir
Exploit-DB
Homematic CCU2 2.29.23 - Arbitrary File Write
CVE-2018-730030 mar 2018
Directory Traversal / Arbitrary File Write / Remote Code Execution in the User.setLanguage method in eQ-3 AG Homematic C
35RIESGO
abrir
Exploit-DB
Homematic CCU2 2.29.23 - Remote Command Execution
CVE-2018-729730 mar 2018
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers
35RIESGO
abrir
Exploit-DB
Vtiger CRM 6.3.0 - (Authenticated) Arbitrary File Upload (Metasploit)
CVE-2016-171330 mar 2018
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger
43RIESGO
abrir
Exploit-DB
D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router - Authentication Bypass
CVE-2018-903230 mar 2018
An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Versi
28RIESGO
abrir
Exploit-DB
Joomla! Component AcySMS 3.5.0 - CSV Macro Injection
CVE-2018-910630 mar 2018
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extensio
23RIESGO
abrir
Exploit-DB
WordPress Plugin Contact Form 7 to Database Extension 2.10.32 - CSV Injection
CVE-2018-903530 mar 2018
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPr
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.