Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
systemd - Lack of Seat Verification in PAM Module Permits Spoofing Active Session to polkit
CVE-2019-3842MEDIUMdoslinux23 abr 2019
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using t
33RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Business Intelligence 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - Directory Traversal
CVE-2019-2588webappswindows19 abr 2019
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
50RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection
CVE-2019-2616HIGHbajo ataquewebappswindows19 abr 2019
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
100RIESGO
abrir
Exploit-DBVexDay Proof
Atlassian Confluence Widget Connector Macro - Velocity Template Injection (Metasploit)
CVE-2019-3396CRITICALbajo ataqueransomwareremotemultiple19 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
Exploit-DBVexDay Proof
SystemTap 1.3 - MODPROBE_OPTIONS Privilege Escalation (Metasploit)
CVE-2010-4170locallinux19 abr 2019
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RIESGO
abrir
Exploit-DBVexDay Proof
LibreOffice < 6.0.7 / 6.1.3 - Macro Code Execution (Metasploit)
CVE-2018-16858HIGHlocalmultiple18 abr 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Java Runtime Environment - Heap Corruption During TTF font Rendering in sc_FindExtrema4
CVE-2019-2697dosmultiple17 abr 2019
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Ja
28RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Java Runtime Environment - Heap Corruption During TTF font Rendering in GlyphIterator::setCurrGlyphID
CVE-2019-2698dosmultiple17 abr 2019
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Ja
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV Delayed Virtualization Cross Process Handle Duplication Privilege Escalation
CVE-2019-0731localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 / 1709 - CSRSS SxSSrv Cached Manifest Privilege Escalation
CVE-2019-0735localwindows16 abr 2019
An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to proper
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV Delayed Virtualization MAXIMUM_ACCESS DesiredAccess Privilege Escalation
CVE-2019-0730localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV LuafvCopyShortName Arbitrary Short Name Privilege Escalation
CVE-2019-0796localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV PostLuafvPostReadWrite SECTION_OBJECT_POINTERS Race Condition Privilege Escalation
CVE-2019-0836localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV NtSetCachedSigningLevel Device Guard Bypass
CVE-2019-0732localwindows16 abr 2019
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Wind
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV Delayed Virtualization Cache Manager Poisoning Privilege Escalation
CVE-2019-0805localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco RV130W Routers - Management Interface Remote Command Execution (Metasploit)
CVE-2019-1663CRITICALremotehardware15 abr 2019
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir
Exploit-DBVexDay Proof
CuteNews 2.1.2 - 'avatar' Remote Code Execution (Metasploit)
CVE-2019-11447remotephp15 abr 2019
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir
Exploit-DBVexDay Proof
Zimbra Collaboration - Autodiscover Servlet XXE and ProxyServlet SSRF (Metasploit)
CVE-2019-9670CRITICALbajo ataqueremotelinux12 abr 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir
Exploit-DBVexDay Proof
Zimbra Collaboration - Autodiscover Servlet XXE and ProxyServlet SSRF (Metasploit)
CVE-2019-9621HIGHbajo ataqueremotelinux12 abr 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RIESGO
abrir
Exploit-DBVexDay Proof
QNAP Netatalk < 3.1.12 - Authentication Bypass
CVE-2018-1160CRITICALremotemultiple08 abr 2019
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 5.0.0 - Crop-image Shell Upload (Metasploit)
CVE-2019-8943remotephp05 abr 2019
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 5.0.0 - Crop-image Shell Upload (Metasploit)
CVE-2019-8942remotephp05 abr 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JavaScriptCore - 'createRegExpMatchesArray' Type Confusion
CVE-2019-8506HIGHbajo ataquedosmultiple03 abr 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS
76RIESGO
abrir
Exploit-DBVexDay Proof
SpiderMonkey - IonMonkey Compiled Code Fails to Update Inferred Property Types (Type Confusion)
CVE-2019-9813dosmultiple03 abr 2019
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1653HIGHbajo ataqueremotehardware03 abr 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JavaScriptCore - CodeBlock Dangling Watchpoints Use-After-Free
CVE-2019-8558dosmultiple03 abr 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1652HIGHbajo ataqueremotehardware03 abr 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir
Exploit-DBVexDay Proof
iOS < 12.2 / macOS < 10.14.4 XNU - pidversion Increment During execve is Unsafe
CVE-2019-8514dosmultiple03 abr 2019
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JavaScriptCore - Out-Of-Bounds Access in FTL JIT due to LICM Moving Array Access Before the Bounds Check
CVE-2019-8518dosmultiple03 abr 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12
28RIESGO
abrir
Exploit-DBVexDay Proof
CMS Made Simple (CMSMS) Showtime2 - File Upload Remote Code Execution (Metasploit)
CVE-2019-9692remotephp28 mar 2019
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.