Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.836exploits catalogados
32.133CVEs con explotación pública
1932probados en laboratorio
22.786 exploits
Exploit-DB
PlaySMS 1.4 - 'sendfromfile.php?Filename' (Authenticated) 'Code Execution (Metasploit)
CVE-2017-908008 may 2018
PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile
50RIESGO
abrir
Exploit-DB
Palo Alto Networks - 'readSessionVarsFromFile()' Session Corruption (Metasploit)
CVE-2017-15944CRITICALbajo ataque08 may 2018
Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote
100RIESGO
abrir
Exploit-DB
PlaySMS - 'import.php' (Authenticated) CSV File Upload Code Execution (Metasploit)
CVE-2017-910108 may 2018
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User
60RIESGO
abrir
Exploit-DB
2345 Security Guard 3.7 - '2345NetFirewall.sys' Denial of Service
CVE-2018-1080908 may 2018
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD)
23RIESGO
abrir
Exploit-DB
GNU wget - Cookie Injection
CVE-2018-049406 may 2018
GNU Wget before 1.19.5 is prone to a cookie injection vulnerability in the resp_new function in http.c via a \r\n sequen
28RIESGO
abrir
Exploit-DB
CSP MySQL User Manager 2.3.1 - Authentication Bypass
CVE-2018-1075706 may 2018
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a
23RIESGO
abrir
Exploit-DB
DeviceLock Plug and Play Auditor 5.72 - Unicode Buffer Overflow (SEH)
CVE-2018-1065506 may 2018
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RIESGO
abrir
Exploit-DB
Microsoft Windows WMI - Recieve Notification Exploit (Metasploit)
CVE-2016-0040HIGHbajo ataque04 may 2018
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RIESGO
abrir
Exploit-DB
IceWarp Mail Server < 11.1.1 - Directory Traversal
CVE-2015-150304 may 2018
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RIESGO
abrir
Exploit-DB
Google Chrome V8 - Object Allocation Size Integer Overflow
CVE-2018-6065HIGHbajo ataque04 may 2018
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RIESGO
abrir
Exploit-DB
WordPress Plugin WF Cookie Consent 1.1.3 - Cross-Site Scripting
CVE-2018-1037104 may 2018
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin
23RIESGO
abrir
Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
CVE-2018-10561CRITICALbajo ataque03 may 2018
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images
100RIESGO
abrir
Exploit-DB
JasperReports - (Authenticated) File Read
CVE-2018-5430HIGHbajo ataque03 may 2018
TIBCO JasperReports Server Information Disclosure Vulnerability
83RIESGO
abrir
Exploit-DB
GPON Routers - Authentication Bypass / Command Injection
CVE-2018-10562CRITICALbajo ataqueransomware03 may 2018
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
Exploit-DB
WebKit - 'WebCore::jsElementScrollHeightGetter' Use-After-Free
CVE-2018-420002 may 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. Safari before 11.1 is affected. iCloud
23RIESGO
abrir
Exploit-DB
TBK DVR4104 / DVR4216 - Credentials Leak
CVE-2018-999502 may 2018
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
Exploit-DB
Exim < 4.90.1 - 'base64d' Remote Code Execution
CVE-2018-6789CRITICALbajo ataqueransomware02 may 2018
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
Exploit-DB
LibreOffice/Open Office - '.odt' Information Disclosure
CVE-2018-1058302 may 2018
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically p
60RIESGO
abrir
Exploit-DB
Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
CVE-2018-930202 may 2018
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to r
23RIESGO
abrir
Exploit-DB
Norton Core Secure WiFi Router - 'BLE' Command Injection (PoC)
CVE-2018-523402 may 2018
The Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in whic
28RIESGO
abrir
Exploit-DB
WordPress Plugin Responsive Cookie Consent 1.7 / 1.6 / 1.5 - (Authenticated) Persistent Cross-Site Scripting
CVE-2018-1030901 may 2018
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
23RIESGO
abrir
Exploit-DB
Drupal < 7.58 - 'Drupalgeddon3' (Authenticated) Remote Code (Metasploit)
CVE-2018-7602CRITICALbajo ataqueransomware30 abr 2018
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
100RIESGO
abrir
Exploit-DB
Apple macOS 10.13.2 - Double mach_port_deallocate in kextd due to Failure to Comply with MIG Ownership Rules
CVE-2018-413930 abr 2018
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "kext tools"
23RIESGO
abrir
Exploit-DB
Apple macOS/iOS - ReportCrash mach port Replacement due to Failure to Respect MIG Ownership Rules
CVE-2018-420630 abr 2018
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RIESGO
abrir
Exploit-DB
WordPress Plugin Form Maker 1.12.20 - CSV Injection
CVE-2018-1050430 abr 2018
The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.
23RIESGO
abrir
Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-873530 abr 2018
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
50RIESGO
abrir
Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-873430 abr 2018
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RIESGO
abrir
Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-873330 abr 2018
Authentication bypass vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an
43RIESGO
abrir
Exploit-DB
Nagios XI 5.2.6 < 5.2.9 / 5.3 / 5.4 - Chained Remote Root
CVE-2018-873630 abr 2018
A privilege escalation vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to leverage an RC
50RIESGO
abrir
Exploit-DB
Jfrog Artifactory < 4.16 - Arbitrary File Upload / Remote Command Execution
CVE-2016-1003626 abr 2018
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.