Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
IBM TM1 / Planning Analytics Unauthenticated Remote Code Execution
CVE-2019-4716CRITICALbajo ataque19 dic 2019
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated use
100RIESGO
abrir
Metasploit600
Citrix ADC (NetScaler) Directory Traversal RCE
CVE-2019-19781CRITICALbajo ataqueransomware17 dic 2019
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
Metasploit300
Citrix ADC (NetScaler) Directory Traversal Scanner
CVE-2019-19781CRITICALbajo ataqueransomware17 dic 2019
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
Metasploit300
TVT NVMS-1000 Directory Traversal
CVE-2019-20085HIGHbajo ataque12 dic 2019
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
Metasploit600
OpenBSD Dynamic Loader chpass Privilege Escalation
CVE-2019-1972611 dic 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir
Metasploit300
Microsoft Windows Uninitialized Variable Local Privilege Elevation
CVE-2019-1458HIGHbajo ataqueransomware10 dic 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Metasploit600
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
CVE-2017-11317CRITICALbajo ataque09 dic 2019
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir
Metasploit600
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
CVE-2019-18935CRITICALbajo ataqueransomware09 dic 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
Metasploit300
Anviz CrossChex Buffer Overflow
CVE-2019-1251828 nov 2019
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
50RIESGO
abrir
Metasploit300
QNAP QTS and Photo Station Local File Inclusion
CVE-2019-7192CRITICALbajo ataqueransomware25 nov 2019
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RIESGO
abrir
Metasploit300
QNAP QTS and Photo Station Local File Inclusion
CVE-2019-7194CRITICALbajo ataqueransomware25 nov 2019
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RIESGO
abrir
Metasploit300
QNAP QTS and Photo Station Local File Inclusion
CVE-2019-7195CRITICALbajo ataqueransomware25 nov 2019
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RIESGO
abrir
Metasploit600
Liferay Portal Java Unmarshalling via JSONWS RCE
CVE-2020-7961CRITICALbajo ataque25 nov 2019
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
Metasploit600
OpenNetAdmin Ping Command Injection
CVE-2019-25065MEDIUM19 nov 2019
OpenNetAdmin os command injection
48RIESGO
abrir
Metasploit300
WordPress Email Subscribers and Newsletter Hash SQLi Scanner
CVE-2019-20361HIGH13 nov 2019
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RIESGO
abrir
Metasploit600
Microsoft UPnP Local Privilege Elevation Vulnerability
CVE-2019-1322HIGHbajo ataqueransomware12 nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RIESGO
abrir
Metasploit600
Microsoft UPnP Local Privilege Elevation Vulnerability
CVE-2019-1405HIGHbajo ataqueransomware12 nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RIESGO
abrir
Metasploit600
Optergy Proton and Enterprise BMS Command Injection using a backdoor
CVE-2019-727605 nov 2019
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RIESGO
abrir
Metasploit600
Microsoft Spooler Local Privilege Elevation Vulnerability
CVE-2020-1337HIGH04 nov 2019
Windows Print Spooler Elevation of Privilege Vulnerability
41RIESGO
abrir
Metasploit600
Windows Update Orchestrator unchecked ScheduleWork call
CVE-2020-131304 nov 2019
An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file oper
30RIESGO
abrir
Metasploit300
Microsoft Spooler Local Privilege Elevation Vulnerability
CVE-2020-1048HIGH04 nov 2019
Windows Print Spooler Elevation of Privilege Vulnerability
61RIESGO
abrir
Metasploit600
FreeSWITCH Event Socket Command Execution
CVE-2019-1949203 nov 2019
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
43RIESGO
abrir
Metasploit0
Kibana Timelion Prototype Pollution RCE
CVE-2019-7609CRITICALbajo ataque30 oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
Metasploit600
Apache Solr Remote Code Execution via Velocity Template
CVE-2019-17558HIGHbajo ataque29 oct 2019
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
Metasploit600
Linear eMerge E3-Series Access Controller Command Injection
CVE-2019-7256CRITICALbajo ataque29 oct 2019
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir
Metasploit600
rConfig install Command Execution
CVE-2019-1666228 oct 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
Metasploit300
PHP-FPM Underflow RCE
CVE-2019-11043HIGHbajo ataqueransomware22 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Metasploit400
Nostromo Directory Traversal Remote Command Execution
CVE-2019-16278CRITICALbajo ataque20 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
Metasploit600
Solaris xscreensaver log Privilege Escalation
CVE-2019-3010HIGHbajo ataque16 oct 2019
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir
Metasploit300
ThinVNC Directory Traversal
CVE-2019-1766216 oct 2019
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.