Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Homematic CCU2 2.29.23 - Remote Command Execution
CVE-2018-729730 mar 2018
Remote Code Execution in the TCL script interpreter in eQ-3 AG Homematic CCU2 2.29.2 and earlier allows remote attackers
35RIESGO
abrir
Exploit-DB
Joomla! Component AcySMS 3.5.0 - CSV Macro Injection
CVE-2018-910630 mar 2018
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extensio
23RIESGO
abrir
Exploit-DB
Systematic SitAware - NVG Denial of Service
CVE-2018-911530 mar 2018
Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG
23RIESGO
abrir
Exploit-DB
MiniCMS 1.10 - Cross-Site Request Forgery
CVE-2018-909230 mar 2018
There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
23RIESGO
abrir
Exploit-DB
Cisco Smart Install - Crash (PoC)
CVE-2018-0171HIGHbajo ataque29 mar 2018
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentica
100RIESGO
abrir
Exploit-DB
Joomla! Component Fields - SQLi Remote Code Execution (Metasploit)
CVE-2017-891729 mar 2018
SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspeci
60RIESGO
abrir
Exploit-DB
Exodus Wallet (ElectronJS Framework) - Remote Code Execution (Metasploit)
CVE-2018-100000629 mar 2018
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RIESGO
abrir
Exploit-DB
GitStack - Unsanitized Argument Remote Code Execution (Metasploit)
CVE-2018-595529 mar 2018
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RIESGO
abrir
Exploit-DB
Microsoft Windows Remote Assistance - XML External Entity Injection
CVE-2018-0878LOW28 mar 2018
Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Window
33RIESGO
abrir
Exploit-DB
TwonkyMedia Server 7.0.11-8.5 - Persistent Cross-Site Scripting
CVE-2018-720328 mar 2018
Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DB
TwonkyMedia Server 7.0.11-8.5 - Directory Traversal
CVE-2018-717128 mar 2018
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of a
28RIESGO
abrir
Exploit-DB
Open-AuditIT Professional 2.1 - Cross-Site Scripting
CVE-2018-890328 mar 2018
Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.
23RIESGO
abrir
Exploit-DB
DLINK DCS-5020L - Remote Code Execution (PoC)
CVE-2017-1702027 mar 2018
On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DC
28RIESGO
abrir
Exploit-DB
Microsoft Windows Manager (7 x86) - Menu Management Component UAF Privilege Elevation
CVE-2017-0263HIGHbajo ataque26 mar 2018
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RIESGO
abrir
Exploit-DB
Laravel Log Viewer < 0.13.0 - Local File Download
CVE-2018-894726 mar 2018
rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easi
28RIESGO
abrir
Exploit-DB
Acrolinx Server < 5.2.5 - Directory Traversal
CVE-2018-771926 mar 2018
Acrolinx Server before 5.2.5 on Windows allows Directory Traversal.
50RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
CVE-2017-1325823 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RIESGO
abrir
Exploit-DB
Dell EMC NetWorker - Denial of Service
CVE-2018-121823 mar 2018
In Dell EMC NetWorker versions prior to 9.2.1.1, versions prior to 9.1.1.6, 9.0.x, and versions prior to 8.2.4.11, the '
28RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
CVE-2017-1326223 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
CVE-2017-1326223 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing length decrement operation. Th
23RIESGO
abrir
Exploit-DB
WordPress Plugin Site Editor 1.1.1 - Local File Inclusion
CVE-2018-742223 mar 2018
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
CVE-2017-1326123 mar 2018
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. T
23RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
CVE-2017-1326123 mar 2018
In bnep_process_control_packet of bnep_utils.cc, there is a possible out of bounds read due to a missing bounds check. T
23RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
CVE-2017-1325823 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP bnep_data_ind() Remote Heap Disclosure
CVE-2017-1326023 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RIESGO
abrir
Exploit-DB
Android Bluetooth - BNEP BNEP_SETUP_CONNECTION_REQUEST_MSG Out-of-Bounds Read
CVE-2017-1326023 mar 2018
In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead
23RIESGO
abrir
Exploit-DB
Linux Kernel < 4.15.4 - 'show_floppy' KASLR Address Leak
CVE-2018-727322 mar 2018
In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables usi
23RIESGO
abrir
Exploit-DB
Internet Explorer - 'RegExp.lastMatch' Memory Disclosure
CVE-2018-089120 mar 2018
ChakraCore, and Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT
28RIESGO
abrir
Exploit-DB
Microsoft Windows Kernel - 'nt!NtWaitForDebugEvent' 64-bit Stack Memory Disclosure
CVE-2018-090120 mar 2018
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RIESGO
abrir
Exploit-DB
Coship RT3052 Wireless Router - Persistent Cross-Site Scripting
CVE-2018-877220 mar 2018
Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.