Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Jorani Leave Management 0.6.5 - Cross-Site Scripting
CVE-2018-1591706 sep 2018
Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HT
38RIESGO
abrir
Exploit-DB
Cisco Umbrella Roaming Client 2.0.168 - Local Privilege Escalation
CVE-2018-043806 sep 2018
Cisco Umbrella Enterprise Roaming Client Privilege Escalation Vulnerability
23RIESGO
abrir
Exploit-DB
Jorani Leave Management 0.6.5 - (Authenticated) 'startdate' SQL Injection
CVE-2018-1591806 sep 2018
An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permission
23RIESGO
abrir
Exploit-DB
Apache Roller 5.0.3 - XML External Entity Injection (File Disclosure)
CVE-2014-003006 sep 2018
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks
28RIESGO
abrir
Exploit-DB
WirelessHART Fieldgate SWG70 3.0 - Directory Traversal
CVE-2018-1605906 sep 2018
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename par
43RIESGO
abrir
Exploit-DB
Cisco Umbrella Roaming Client 2.0.168 - Local Privilege Escalation
CVE-2018-043706 sep 2018
Cisco Umbrella Enterprise Roaming Client and Enterprise Roaming Module Privilege Escalation Vulnerability
23RIESGO
abrir
Exploit-DB
Tenda ADSL Router D152 - Cross-Site Scripting
CVE-2018-1449705 sep 2018
Tenda D152 ADSL routers allow XSS via a crafted SSID.
23RIESGO
abrir
Exploit-DB
FsPro Labs Event Log Explorer v4.6.1.2115 - XML External Entity Injection
CVE-2018-1625203 sep 2018
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RIESGO
abrir
Exploit-DB
D-Link DIR-615 - Denial of Service (PoC)
CVE-2018-1583903 sep 2018
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
35RIESGO
abrir
Exploit-DB
Network Manager VPNC 1.2.6 - 'Username' Local Privilege Escalation (Metasploit)
CVE-2018-10900HIGH31 ago 2018
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac
56RIESGO
abrir
Exploit-DB
DamiCMS 6.0.0 - Cross-Site Request Forgery (Change Admin Password)
CVE-2018-1584431 ago 2018
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's pas
23RIESGO
abrir
Exploit-DB
DLink DIR-601 - Credential Disclosure
CVE-2018-1271030 ago 2018
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (whi
45RIESGO
abrir
Exploit-DB
Cybrotech CyBroHttpServer 1.0.3 - Directory Traversal
CVE-2018-1613330 ago 2018
Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.
50RIESGO
abrir
Exploit-DB
Cybrotech CyBroHttpServer 1.0.3 - Cross-Site Scripting
CVE-2018-1613430 ago 2018
Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.
23RIESGO
abrir
Exploit-DB
Argus Surveillance DVR 4.0.0.0 - Directory Traversal
CVE-2018-1574529 ago 2018
Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F
60RIESGO
abrir
Exploit-DB
phpMyAdmin 4.7.x - Cross-Site Request Forgery
CVE-2017-100049929 ago 2018
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a
23RIESGO
abrir
Exploit-DB
Microsoft Windows - JScript RegExp.lastIndex Use-After-Free
CVE-2018-835328 ago 2018
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RIESGO
abrir
Exploit-DB
WordPress Plugin Plainview Activity Monitor 20161228 - (Authenticated) Command Injection
CVE-2018-1587727 ago 2018
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RIESGO
abrir
Exploit-DB
Responsive FileManager < 9.13.4 - Directory Traversal
CVE-2018-1553627 ago 2018
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc
23RIESGO
abrir
Exploit-DB
Gleez CMS 1.2.0 - Cross-Site Request Forgery (Add Admin)
CVE-2018-1584527 ago 2018
There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
23RIESGO
abrir
Exploit-DB
RICOH MP C4504ex Printer - Cross-Site Request Forgery (Add Admin)
CVE-2018-1588427 ago 2018
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RIESGO
abrir
Exploit-DB
Electron WebPreferences - Remote Code Execution
CVE-2018-1568527 ago 2018
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindow
28RIESGO
abrir
Exploit-DB
HP Jetdirect - Path Traversal Arbitrary Code Execution (Metasploit)
CVE-2017-274127 ago 2018
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RIESGO
abrir
Exploit-DB
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-995827 ago 2018
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir
Exploit-DB
Adobe Flash - AVC Processing Out-of-Bounds Read
CVE-2018-1282727 ago 2018
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead t
35RIESGO
abrir
Exploit-DB
Responsive FileManager < 9.13.4 - Directory Traversal
CVE-2018-1553527 ago 2018
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname
50RIESGO
abrir
Exploit-DB
Foxit PDF Reader 9.0.1.1049 - Pointer Overwrite Use-After-Free (Metasploit)
CVE-2018-994827 ago 2018
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
Exploit-DB
ManageEngine ADManager Plus 6.5.7 - Cross-Site Scripting
CVE-2018-1574026 ago 2018
Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
23RIESGO
abrir
Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (1)
CVE-2018-11776HIGHbajo ataque26 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DB
Apache Struts 2.3 < 2.3.34 / 2.5 < 2.5.16 - Remote Code Execution (2)
CVE-2018-11776HIGHbajo ataque25 ago 2018
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.