Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.066exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
8410 exploits
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware15 mar 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware15 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware11 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-19276CRITICAL11 mar 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-019210 mar 2019
In Apache Solr versions 5.0.0 to 5.5.5 and 6.0.0 to 6.6.5, the Config API allows to configure the JMX server via an HTTP
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-1724608 mar 2019
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-100300006 mar 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware05 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8639HIGHbajo ataqueransomware05 mar 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware05 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware04 mar 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware28 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-7238CRITICALbajo ataque24 feb 2019
Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware23 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-6340HIGHbajo ataque23 feb 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware22 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-573620 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-100300015 feb 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
VulnCheck XDB
local
CVE-2019-573614 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
VulnCheck XDB
local
CVE-2019-573613 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
VulnCheck XDB
local
CVE-2019-573612 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-6961HIGHbajo ataque08 feb 2019
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1653HIGHbajo ataque30 ene 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-999528 ene 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-1885226 ene 2019
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-in
35RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-1653HIGHbajo ataque24 ene 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-8581HIGHbajo ataqueransomware24 ene 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-1652HIGHbajo ataque24 ene 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALbajo ataqueransomware20 ene 2019
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-8174HIGHbajo ataqueransomware20 ene 2019
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
anteriorpágina 264 / 281siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.