Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12989CRITICALbajo ataquewebappscgi12 jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling due to Out-of-Bounds cubeStackDepth
CVE-2019-1117doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Empty ROS Strings
CVE-2019-1124doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Unbounded iFD
CVE-2019-1121doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readFDSelect
CVE-2019-1120doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readStrings
CVE-2019-1122doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Negative cubeStackDepth
CVE-2019-1118doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readCharset
CVE-2019-1128doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Negative nAxes
CVE-2019-1127doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Incorrect Handling of blendArray
CVE-2019-1119doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling While Processing CFF Blend DICT Operator
CVE-2019-1123doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat - CGIServlet enableCmdLineArguments Remote Code Execution (Metasploit)
CVE-2019-0232remotewindows03 jul 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
Exploit-DBVexDay Proof
Serv-U FTP Server - prepareinstallation Privilege Escalation (Metasploit)
CVE-2019-12181locallinux03 jul 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir
Exploit-DBVexDay Proof
Mac OS X TimeMachine - 'tmdiagnose' Command Injection Privilege Escalation (Metasploit)
CVE-2019-8513localmacos02 jul 2019
This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to
38RIESGO
abrir
Exploit-DBVexDay Proof
LibreNMS 1.46 - 'addhost' Remote Code Execution
CVE-2018-20434webappsphp28 jun 2019
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.5.6 - Magpie_debug.php Root Remote Code Execution (Metasploit)
CVE-2018-15710remotelinux26 jun 2019
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.5.6 - Magpie_debug.php Root Remote Code Execution (Metasploit)
CVE-2018-15708remotelinux26 jun 2019
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Spidermonkey - IonMonkey 'Array.prototype.pop' Type Confusion
CVE-2019-11707HIGHbajo ataquedosmultiple26 jun 2019
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'CmpAddRemoveContainerToCLFSLog' Arbitrary File/Directory Creation
CVE-2019-0959HIGHdoswindows24 jun 2019
Windows Common Log File System Driver Elevation of Privilege Vulnerability
41RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Font Cache Service - Insecure Sections Privilege Escalation
CVE-2019-0943doswindows24 jun 2019
Windows ALPC Elevation of Privilege Vulnerability
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Prime Infrastructure Health Monitor - TarArchive Directory Traversal (Metasploit)
CVE-2019-1821HIGHremotelinux20 jun 2019
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RIESGO
abrir
Exploit-DBVexDay Proof
Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (1)
CVE-2019-12181locallinux18 jun 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir
Exploit-DBVexDay Proof
Exim 4.87 - 4.91 - Local Privilege Escalation
CVE-2019-10149CRITICALbajo ataquelocallinux17 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
Exploit-DBVexDay Proof
IBM Websphere Application Server - Network Deployment Untrusted Data Deserialization Remote Code Execution (Metasploit)
CVE-2019-8352remotewindows05 jun 2019
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sen
23RIESGO
abrir
Exploit-DBVexDay Proof
LibreNMS - addhost Command Injection (Metasploit)
CVE-2018-20434remotelinux05 jun 2019
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
50RIESGO
abrir
Exploit-DBVexDay Proof
IBM Websphere Application Server - Network Deployment Untrusted Data Deserialization Remote Code Execution (Metasploit)
CVE-2019-4279CRITICALremotewindows05 jun 2019
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with
85RIESGO
abrir
Exploit-DBVexDay Proof
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
CVE-2018-5406webappsphp03 jun 2019
The Quest Kace K1000 Appliance misconfigures the Cross-Origin Resource Sharing (CORS) mechanism.
28RIESGO
abrir
Exploit-DBVexDay Proof
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
CVE-2018-5405webappsphp03 jun 2019
The Quest Kace K1000 Appliance is vulnerable to JavaScript injection.
23RIESGO
abrir
Exploit-DBVexDay Proof
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
CVE-2018-5404webappsphp03 jun 2019
The Quest Kace K1000 Appliance is vulnerable to multiple Blind SQL Injections.
23RIESGO
abrir
Exploit-DBVexDay Proof
Spidermonkey - IonMonkey Unexpected ObjectGroup in ObjectGroupDispatch Operation
CVE-2019-9816dosmultiple29 may 2019
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, al
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.