Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-1066127 jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
60RIESGO
abrir
Exploit-DB
SoftNAS Cloud < 4.0.3 - OS Command Injection
CVE-2018-1441727 jul 2018
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particul
45RIESGO
abrir
Exploit-DB
Axis Network Camera - .srv to parhand Remote Code Execution (Metasploit)
CVE-2018-1066227 jul 2018
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
60RIESGO
abrir
Exploit-DB
Skia - Heap Overflow in SkScan::FillPath due to Precision Error
CVE-2018-612627 jul 2018
A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds m
23RIESGO
abrir
Exploit-DB
Online Trade 1 - Information Disclosure
CVE-2018-1432827 jul 2018
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensiti
28RIESGO
abrir
Exploit-DB
Trivum Multiroom Setup Tool 8.76 - Corss-Site Request Forgery (Admin Bypass)
CVE-2018-1385926 jul 2018
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, all
28RIESGO
abrir
Exploit-DB
GetGo Download Manager 6.2.1.3200 - Denial of Service (PoC)
CVE-2017-1784925 jul 2018
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to exec
28RIESGO
abrir
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-1344124 jul 2018
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows atta
23RIESGO
abrir
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-1345824 jul 2018
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RIESGO
abrir
Exploit-DB
Nagios Core 4.4.1 - Denial of Service
CVE-2018-1345724 jul 2018
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RIESGO
abrir
Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
CVE-2018-12465CRITICAL24 jul 2018
Remote Code Execution in Micro Focus Secure Messaging Gateway
85RIESGO
abrir
Exploit-DB
Micro Focus Secure Messaging Gateway (SMG) < 471 - Remote Code Execution (Metasploit)
CVE-2018-12464CRITICAL24 jul 2018
Unauthenticated SQL injection in Micro Focus Secure Messaging Gateway
85RIESGO
abrir
Exploit-DB
Tenda Wireless N150 Router 5.07.50 - Cross-Site Request Forgery (Reboot Router)
CVE-2015-599623 jul 2018
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allo
23RIESGO
abrir
Exploit-DB
Davolink DVW 3200 Router - Password Disclosure
CVE-2018-1061823 jul 2018
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracke
28RIESGO
abrir
Exploit-DB
Inteno’s IOPSYS - (Authenticated) Local Privilege Escalation
CVE-2018-1453321 jul 2018
read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /v
23RIESGO
abrir
Exploit-DB
Touchpad / Trivum WebTouch Setup 2.53 build 13163 - Authentication Bypass
CVE-2018-1386220 jul 2018
Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attacker
35RIESGO
abrir
Exploit-DB
TP-Link TL-WR840N - Denial of Service
CVE-2018-1433620 jul 2018
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets w
23RIESGO
abrir
Exploit-DB
MSVOD 10 - 'cid' SQL Injection
CVE-2018-1441820 jul 2018
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
23RIESGO
abrir
Exploit-DB
WordPress Plugin All In One Favicon 4.6 - (Authenticated) Cross-Site Scripting
CVE-2018-1383219 jul 2018
Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plu
23RIESGO
abrir
Exploit-DB
Linux - BPF Sign Extension Local Privilege Escalation (Metasploit)
CVE-2017-1699519 jul 2018
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
Exploit-DB
MyBB New Threads Plugin 1.1 - Cross-Site Scripting
CVE-2018-1439219 jul 2018
The New Threads plugin before 1.2 for MyBB has XSS.
35RIESGO
abrir
Exploit-DB
Open-AudIT Community 2.1.1 - Cross-Site Scripting
CVE-2018-1112418 jul 2018
Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows
23RIESGO
abrir
Exploit-DB
Nanopool Claymore Dual Miner - APIs Remote Code Execution (Metasploit)
CVE-2018-100004917 jul 2018
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner
60RIESGO
abrir
Exploit-DB
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
CVE-2018-070717 jul 2018
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
50RIESGO
abrir
Exploit-DB
QNAP Q'Center - 'change_passwd' Command Execution (Metasploit)
CVE-2018-070617 jul 2018
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticate
50RIESGO
abrir
Exploit-DB
VelotiSmart WiFi B-380 Camera - Directory Traversal
CVE-2018-1406416 jul 2018
The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../..
50RIESGO
abrir
Exploit-DB
Linux (Ubuntu) - Other Users coredumps Can Be Read via setgid Directory and killpriv Bypass
CVE-2018-1340516 jul 2018
The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an
23RIESGO
abrir
Exploit-DB
PrestaShop < 1.6.1.19 - 'AES CBC' Privilege Escalation
CVE-2018-1378416 jul 2018
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RIESGO
abrir
Exploit-DB
PrestaShop < 1.6.1.19 - 'BlowFish ECD' Privilege Escalation
CVE-2018-1378416 jul 2018
PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfi
28RIESGO
abrir
Exploit-DB
Fortify Software Security Center (SSC) 17.x/18.1 - XML External Entity Injection
CVE-2018-12463HIGH16 jul 2018
MFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
46RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.