Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Static Buffer Overflow due to Malformed Font Stream
CVE-2019-8048doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap-Based Out-of-Bounds read in WriteTableFromStructure
CVE-2019-1150HIGHdoswindows15 ago 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Memory Corruption due to Malformed TTF Font
CVE-2019-8042doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Returning a Dangling Pointer via MergeFontPackage
CVE-2019-1145HIGHdoswindows15 ago 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - UXSS via XSLT and Nested Document Replacements
CVE-2019-8690dosmultiple12 ago 2019
A logic issue existed in the handling of document loads. This issue was addressed with improved state management. This i
23RIESGO
abrir
Exploit-DBVexDay Proof
Ghidra (Linux) 9.0.4 - .gar Arbitrary Code Execution
CVE-2019-13623locallinux12 ago 2019
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)
23RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit)
CVE-2018-1335remotewindows05 ago 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Exploit-DBVexDay Proof
macOS iMessage - Heap Overflow when Deserializing
CVE-2019-8661dosmacos05 ago 2019
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Hyperion Planning 11.1.2.3 - XML External Entity
CVE-2019-2861webappsmultiple31 jul 2019
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported versi
23RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - NSArray Deserialization can Invoke Subclass that does not Retain References
CVE-2019-8647dosmultiple30 jul 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchO
28RIESGO
abrir
Exploit-DBVexDay Proof
macOS / iOS JavaScriptCore - Loop-Invariant Code Motion (LICM) Leaves Object Property Access Unguarded
CVE-2019-8671dosmultiple30 jul 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
23RIESGO
abrir
Exploit-DBVexDay Proof
macOS / iOS JavaScriptCore - JSValue Use-After-Free in ValueProfiles
CVE-2019-8672dosmultiple30 jul 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
28RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - NSKeyedUnarchiver Deserialization Allows file Backed NSData Objects
CVE-2019-8646dosmultiple30 jul 2019
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.
28RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - Memory Corruption when Decoding NSKnownKeysDictionary1
CVE-2019-8660dosmultiple30 jul 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10
28RIESGO
abrir
Exploit-DBVexDay Proof
macOS / iOS NSKeyedUnarchiver - Use-After-Free of ObjC Objects when Unarchiving OITSUIntDictionary Instances
CVE-2019-8662dosmultiple30 jul 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
CVE-2019-3948webappshardware30 jul 2019
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0
28RIESGO
abrir
Exploit-DBVexDay Proof
Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass (Metasploit)
CVE-2019-6814remoteunix29 jul 2019
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RIESGO
abrir
Exploit-DBVexDay Proof
pdfresurrect 0.15 - Buffer Overflow
CVE-2019-14267doslinux26 jul 2019
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RIESGO
abrir
Exploit-DBVexDay Proof
Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
CVE-2019-10267webappsjsp26 jul 2019
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - Universal Cross-Site Scripting due to Synchronous Page Loads
CVE-2019-8649dosmultiple25 jul 2019
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple iMessage - DigitalTouch tap Message Processing Out-of-Bounds Read
CVE-2019-8624doswatchos24 jul 2019
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacke
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1903/1809 - RPCSS Activation Kernel Security Callback Privilege Escalation
CVE-2019-1089localwindows18 jul 2019
An elevation of privilege vulnerability exists in rpcss.dll when the RPC service Activation Kernel improperly handles an
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtUserSetWindowFNID Win32k User Callback Privilege Escalation (Metasploit)
CVE-2018-8453HIGHbajo ataqueransomwarelocalwindows17 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Exploit-DBVexDay Proof
Linux - Broken Permission and Object Lifetime Handling for PTRACE_TRACEME
CVE-2019-13272HIGHbajo ataquelocallinux17 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 < build 17763 - AppXSvc Hard Link Privilege Escalation (Metasploit)
CVE-2019-0841HIGHbajo ataqueransomwarelocalwindows16 jul 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2017-16894remotelinux16 jul 2019
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RIESGO
abrir
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2018-15133HIGHbajo ataqueremotelinux16 jul 2019
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12989CRITICALbajo ataquewebappscgi12 jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
100RIESGO
abrir
Exploit-DBVexDay Proof
Xymon 4.3.25 - useradm Command Execution (Metasploit)
CVE-2016-2056remotemultiple12 jul 2019
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via
50RIESGO
abrir
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12991HIGHbajo ataquewebappscgi12 jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of
93RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.