Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.886exploits catalogados
32.153CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Sync Breeze Enterprise 10.1.16 - Denial of Service
CVE-2017-1566408 ene 2018
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The at
23RIESGO
abrir
Exploit-DB
Synology DiskStation Manager (DSM) < 6.1.3-15152 - 'forget_passwd.cgi' User Enumeration
CVE-2017-955408 ene 2018
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-1688508 ene 2018
Improper Permissions Handling in the Portal on FiberHome LM53Q1 VH519R05C01S38 devices (intended for obtaining informati
35RIESGO
abrir
Exploit-DB
Vanilla < 2.1.5 - Cross-Site Request Forgery
CVE-2017-100043208 ene 2018
Vanilla Forums below 2.1.5 are affected by CSRF leading to Deleting topics and comments from forums Admin access
23RIESGO
abrir
Exploit-DB
VX Search Enterprise 10.1.12 - Denial of Service
CVE-2017-1566208 ene 2018
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The atta
23RIESGO
abrir
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-1688708 ene 2018
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
35RIESGO
abrir
Exploit-DB
Disk Pulse Enterprise 10.1.18 - Denial of Service
CVE-2017-1566308 ene 2018
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The att
28RIESGO
abrir
Exploit-DB
FiberHome LM53Q1 - Multiple Vulnerabilities
CVE-2017-1688608 ene 2018
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact
23RIESGO
abrir
Exploit-DB
Microsoft Windows win32k - Using SetClassLong to Switch Between CS_CLASSDC and CS_OWNDC Corrupts DC Cache
CVE-2018-074405 ene 2018
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
28RIESGO
abrir
Exploit-DB
Gespage 7.4.8 - SQL Injection
CVE-2017-799705 ene 2018
Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands
28RIESGO
abrir
Exploit-DB
gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
CVE-2017-1709705 ene 2018
gps-server.net GPS Tracking Software (self hosted) 2.x has a password reset procedure that immediately resets passwords
23RIESGO
abrir
Exploit-DB
gps-server.net GPS Tracking Software < 3.1 - Multiple Vulnerabilities
CVE-2017-1709805 ene 2018
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote a
23RIESGO
abrir
Exploit-DB
Ayukov NFTP FTP Client 2.0 - Remote Buffer Overflow (Metasploit)
CVE-2017-1522205 ene 2018
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RIESGO
abrir
Exploit-DB
Cisco IOS - Remote Code Execution
CVE-2017-6736HIGHbajo ataque05 ene 2018
The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabiliti
93RIESGO
abrir
Exploit-DB
Linksys WVBR0-25 - User-Agent Command Execution (Metasploit)
CVE-2017-1741104 ene 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RIESGO
abrir
Exploit-DB
Xplico - Remote Code Execution (Metasploit)
CVE-2017-1666604 ene 2018
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name
60RIESGO
abrir
Exploit-DB
Oracle WebLogic < 10.3.6 - 'wls-wsat' Component Deserialisation Remote Command Execution
CVE-2017-10271HIGHbajo ataqueransomware03 ene 2018
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure
CVE-2017-5715MEDIUM03 ene 2018
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
Exploit-DB
Multiple CPUs - 'Spectre' Information Disclosure
CVE-2017-5753MEDIUM03 ene 2018
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
Exploit-DB
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection
CVE-2018-381003 ene 2018
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RIESGO
abrir
Exploit-DB
EMC xPression 4.5SP1 Patch 13 - 'model.jobHistoryId' SQL Injection
CVE-2017-1496003 ene 2018
xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL I
23RIESGO
abrir
Exploit-DB
WordPress Plugin Smart Google Code Inserter < 3.5 - Authentication Bypass / SQL Injection
CVE-2018-381103 ene 2018
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthentica
35RIESGO
abrir
Exploit-DB
HP Mercury LoadRunner Agent magentproc.exe - Remote Command Execution (Metasploit)
CVE-2010-154901 ene 2018
Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote
60RIESGO
abrir
Exploit-DB
Cambium ePMP1000 - 'get_chart' Shell via Command Injection (Metasploit)
CVE-2017-525501 ene 2018
In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web
60RIESGO
abrir
Exploit-DB
PHP Melody 2.7.1 - 'playlist' SQL Injection
CVE-2018-521131 dic 2017
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
23RIESGO
abrir
Exploit-DB
NetTransport 2.96L - Remote Buffer Overflow (DEP Bypass)
CVE-2017-1796829 dic 2017
A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remot
50RIESGO
abrir
Exploit-DB
ALLMediaServer 0.95 - Remote Buffer Overflow (Metasploit)
CVE-2017-1793228 dic 2017
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RIESGO
abrir
Exploit-DB
ALLMediaServer 0.95 - Buffer Overflow (PoC)
CVE-2017-1793227 dic 2017
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow
50RIESGO
abrir
Exploit-DB
SysGauge Server 3.6.18 - Denial of Service
CVE-2017-1566727 dic 2017
In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafte
23RIESGO
abrir
Exploit-DB
Ubiquiti UniFi Video 3.7.3 - Local Privilege Escalation
CVE-2016-691426 dic 2017
Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local u
23RIESGO
abrir
anteriorpágina 110 / 760siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.