Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Ajenti auth username Command Injection
CVE-2019-25066MEDIUM14 oct 2019
ajenti API privileges management
28RIESGO
abrir
Metasploit600
Android Binder Use-After-Free Exploit
CVE-2019-2215HIGHbajo ataque26 sep 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
Metasploit300
File Sharing Wizard - POST SEH Overflow
CVE-2019-1672424 sep 2019
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RIESGO
abrir
Metasploit600
vBulletin widgetConfig RCE
CVE-2019-16759CRITICALbajo ataque23 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Metasploit600
PHPStudy Backdoor Remote Code execution
CVE-2025-34061CRITICAL20 sep 2019
PHPStudy 2016-2018 Backdoor Remote Code Execution Vulnerability
63RIESGO
abrir
Metasploit600
Micro Focus (HPE) Data Protector SUID Privilege Escalation
CVE-2019-1166013 sep 2019
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RIESGO
abrir
Metasploit600
Bludit Directory Traversal Image File Upload Vulnerability
CVE-2019-1611307 sep 2019
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
Metasploit300
Metasploit HTTP(S) handler DoS
CVE-2019-5645HIGH04 sep 2019
Rapid7 Metasploit HTTP Handler Denial of Service
48RIESGO
abrir
Metasploit600
Total.js CMS 12 Widget JavaScript Code Injection
CVE-2019-1595430 ago 2019
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote
60RIESGO
abrir
Metasploit600
Plantronics Hub SpokesUpdateService Privilege Escalation
CVE-2019-1574230 ago 2019
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application
38RIESGO
abrir
Metasploit600
Cisco UCS Director Unauthenticated Remote Code Execution
CVE-2019-1937CRITICAL21 ago 2019
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass Vulnerability
85RIESGO
abrir
Metasploit600
Cisco UCS Director Unauthenticated Remote Code Execution
CVE-2019-1936HIGH21 ago 2019
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Command Injection Vulnerability
48RIESGO
abrir
Metasploit600
Cisco UCS Director default scpuser password
CVE-2019-1935CRITICAL21 ago 2019
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
85RIESGO
abrir
Metasploit300
Grafana 2.0 through 5.2.2 authentication bypass for LDAP and OAuth
CVE-2018-1572714 ago 2019
Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generat
30RIESGO
abrir
Metasploit600
Webmin password_change.cgi Backdoor
CVE-2019-15107CRITICALbajo ataqueransomware10 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
Metasploit300
URGENT/11 Scanner, Based on Detection Tool by Armis
CVE-2019-1225809 ago 2019
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: Do
23RIESGO
abrir
Metasploit600
Nagios XI Prior to 5.6.6 getprofile.sh Authenticated Remote Command Execution
CVE-2019-15949HIGHbajo ataque29 jul 2019
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios
100RIESGO
abrir
Metasploit300
LibreOffice Macro Python Code Execution
CVE-2019-985116 jul 2019
LibreLogo global-event script execution
60RIESGO
abrir
Metasploit600
LibreNMS Collectd Command Injection
CVE-2019-1066915 jul 2019
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev
60RIESGO
abrir
Metasploit600
D-Link Central WiFi Manager CWM(100) RCE
CVE-2019-1337209 jul 2019
/web/Lib/Action/IndexAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote atta
40RIESGO
abrir
Metasploit300
D-Link Central WiFiManager SQL injection
CVE-2019-1337306 jul 2019
An issue was discovered in the D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6. Input does not get validate
30RIESGO
abrir
Metasploit0
Docker-Credential-Wincred.exe Privilege Escalation
CVE-2019-15752HIGHbajo ataque05 jul 2019
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RIESGO
abrir
Metasploit600
Linux Polkit pkexec helper PTRACE_TRACEME local root exploit
CVE-2019-13272HIGHbajo ataque04 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Metasploit300
Cisco Data Center Network Manager Unauthenticated File Download
CVE-2019-1621HIGH26 jun 2019
Cisco Data Center Network Manager Arbitrary File Download Vulnerability
41RIESGO
abrir
Metasploit300
Cisco Data Center Network Manager Unauthenticated File Download
CVE-2019-1619CRITICAL26 jun 2019
Cisco Data Center Network Manager Authentication Bypass Vulnerability
85RIESGO
abrir
Metasploit600
Cisco Data Center Network Manager Unauthenticated Remote Code Execution
CVE-2019-1619CRITICAL26 jun 2019
Cisco Data Center Network Manager Authentication Bypass Vulnerability
85RIESGO
abrir
Metasploit600
Cisco Data Center Network Manager Unauthenticated Remote Code Execution
CVE-2019-1620CRITICAL26 jun 2019
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
85RIESGO
abrir
Metasploit600
Cisco Data Center Network Manager Unauthenticated Remote Code Execution
CVE-2019-1622MEDIUM26 jun 2019
Cisco Data Center Network Manager Information Disclosure Vulnerability
70RIESGO
abrir
Metasploit600
FusionPBX Operator Panel exec.php Command Execution
CVE-2019-1140906 jun 2019
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerabili
60RIESGO
abrir
Metasploit600
Exim 4.87 - 4.91 Local Privilege Escalation
CVE-2019-10149CRITICALbajo ataque05 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.