Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
phpMyAdmin - (Authenticated) Remote Code Execution (Metasploit)
CVE-2018-12613remotephp13 jul 2018
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-12636remotelinux13 jul 2018
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include pa
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - POP/MOV SS Local Privilege Elevation (Metasploit)
CVE-2018-8897localwindows13 jul 2018
A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) wa
43RIESGO
abrir
Exploit-DBVexDay Proof
Apache CouchDB - Arbitrary Command Execution (Metasploit)
CVE-2017-12635remotelinux13 jul 2018
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12980webappsphp13 jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
35RIESGO
abrir
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12981webappsphp13 jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerabilit
23RIESGO
abrir
Exploit-DBVexDay Proof
WAGO e!DISPLAY 7300T - Multiple Vulnerabilities
CVE-2018-12979webappsphp13 jul 2018
An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions
23RIESGO
abrir
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0710webappshardware13 jul 2018
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RIESGO
abrir
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0706webappshardware13 jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RIESGO
abrir
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0707webappshardware13 jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RIESGO
abrir
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0708webappshardware13 jul 2018
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RIESGO
abrir
Exploit-DBVexDay Proof
QNAP Qcenter Virtual Appliance - Multiple Vulnerabilities
CVE-2018-0709webappshardware13 jul 2018
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow auth
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - BoundFunction::NewInstance Out-of-Bounds Read
CVE-2018-8139doswindows12 jul 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Out-of-Bounds Reads/Writes
CVE-2018-8145doswindows12 jul 2018
An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra JIT - Type Confusion with Hoisted SetConcatStrMultiItemBE Instructions
CVE-2018-8229doswindows12 jul 2018
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
Exploit-DBVexDay Proof
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2016-9722remoteunix11 jul 2018
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r
43RIESGO
abrir
Exploit-DBVexDay Proof
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2018-1612MEDIUMremoteunix11 jul 2018
IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and
60RIESGO
abrir
Exploit-DBVexDay Proof
IBM QRadar SIEM - Remote Code Execution (Metasploit)
CVE-2018-1418remoteunix11 jul 2018
IBM Security QRadar SIEM 7.2 and 7.3 could allow a user to bypass authentication which could lead to code execution. IBM
50RIESGO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 4.13.9 (Ubuntu 16.04 / Fedora 27) - Local Privilege Escalation
CVE-2017-16995locallinux10 jul 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
Exploit-DBVexDay Proof
CMS Made Simple 2.2.5 - (Authenticated) Remote Code Execution
CVE-2018-1000094webappsphp04 jul 2018
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows a
50RIESGO
abrir
Exploit-DBVexDay Proof
Boxoft WAV to MP3 Converter 1.1 - Buffer Overflow (Metasploit)
CVE-2015-7243localwindows03 jul 2018
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8734remotelinux02 jul 2018
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8735remotelinux02 jul 2018
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8736remotelinux02 jul 2018
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.2.6-5.4.12 - Chained Remote Code Execution (Metasploit)
CVE-2018-8733remotelinux02 jul 2018
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RIESGO
abrir
Exploit-DBVexDay Proof
VMware NSX SD-WAN Edge < 3.1.2 - Command Injection
CVE-2018-6961HIGHbajo ataquewebappshardware02 jul 2018
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RIESGO
abrir
Exploit-DBVexDay Proof
FTPShell Client 6.70 (Enterprise Edition) - Stack Buffer Overflow (Metasploit)
CVE-2018-7573remotewindows02 jul 2018
An issue was discovered in FTPShell Client 6.7. A remote FTP server can send 400 characters of 'F' in conjunction with t
50RIESGO
abrir
Exploit-DBVexDay Proof
HongCMS 3.0.0 - (Authenticated) SQL Injection
CVE-2018-12912webappsphp28 jun 2018
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via a
23RIESGO
abrir
Exploit-DBVexDay Proof
Quest KACE Systems Management - Command Injection (Metasploit)
CVE-2018-11138CRITICALbajo ataqueransomwareremoteunix27 jun 2018
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by
100RIESGO
abrir
Exploit-DBVexDay Proof
Foxit Reader 9.0.1.1049 - Remote Code Execution
CVE-2018-9948remotewindows25 jun 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.