Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Serv-U FTP Server prepareinstallation Privilege Escalation
CVE-2019-1218105 jun 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir
Metasploit300
Supra Smart Cloud TV Remote File Inclusion
CVE-2019-1247703 jun 2019
Supra Smart Cloud TV allows remote file inclusion in the openLiveURL function, which allows a local attacker to broadcas
43RIESGO
abrir
Metasploit600
Ahsay Backup v7.x-v8.1.1.50 (authenticated) file upload
CVE-2019-1026701 jun 2019
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RIESGO
abrir
Metasploit600
Atlassian Crowd pdkinstall Unauthenticated Plugin Upload RCE
CVE-2019-11580CRITICALbajo ataqueransomware22 may 2019
Atlassian Crowd and Crowd Data Center had the pdkinstall development plugin incorrectly enabled in release builds. Attac
100RIESGO
abrir
Metasploit300
OpenEMR 5.0.1 Patch 6 SQLi Dump
CVE-2018-1717917 may 2019
An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/
23RIESGO
abrir
Metasploit600
ATutor 2.2.4 - Directory Traversal / Remote Code Execution,
CVE-2019-1216917 may 2019
ATutor 2.2.4 allows Arbitrary File Upload and Directory Traversal, resulting in remote code execution via a ".." pathnam
40RIESGO
abrir
Metasploit600
Webmin Package Updates Remote Command Execution
CVE-2019-1284016 may 2019
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
Metasploit600
Cisco Prime Infrastructure Health Monitor TarArchive Directory Traversal Vulnerability
CVE-2019-1821HIGH15 may 2019
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RIESGO
abrir
Metasploit600
DLINK DWL-2600 Authenticated Remote Command Injection
CVE-2019-2049915 may 2019
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Config
60RIESGO
abrir
Metasploit600
IBM Websphere Application Server Network Deployment Untrusted Data Deserialization Remote Code Execution
CVE-2019-4279CRITICAL15 may 2019
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with
85RIESGO
abrir
Metasploit300
CVE-2019-0708 BlueKeep Microsoft Remote Desktop RCE Check
CVE-2019-0708CRITICALbajo ataqueransomware14 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Metasploit0
CVE-2019-0708 BlueKeep RDP Remote Windows Kernel Use After Free
CVE-2019-0708CRITICALbajo ataqueransomware14 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Metasploit600
Shopware createInstanceFromNamedArguments PHP Object Instantiation RCE
CVE-2019-12799MEDIUM09 may 2019
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiat
40RIESGO
abrir
Metasploit600
Shopware createInstanceFromNamedArguments PHP Object Instantiation RCE
CVE-2017-1835709 may 2019
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t
43RIESGO
abrir
Metasploit600
Barco WePresent file_transfer.cgi Command Injection
CVE-2019-3929CRITICALbajo ataque30 abr 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir
Metasploit600
GetSimpleCMS Unauthenticated RCE
CVE-2019-1123128 abr 2019
An issue was discovered in GetSimple CMS through 3.3.15. insufficient input sanitation in the theme-edit.php file allows
60RIESGO
abrir
Metasploit600
Moodle Admin Shell Upload
CVE-2019-1163128 abr 2019
35RIESGO
abrir
Metasploit600
WP Database Backup RCE
CVE-2019-25224CRITICAL24 abr 2019
WP Database Backup < 5.2 - Unauthenticated OS Command Injection
68RIESGO
abrir
Metasploit300
Pulse Secure VPN Arbitrary File Disclosure
CVE-2019-11510CRITICALbajo ataqueransomware24 abr 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Metasploit600
Pulse Secure VPN Arbitrary Command Execution
CVE-2019-11539HIGHbajo ataqueransomware24 abr 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir
Metasploit600
Oracle Weblogic Server Deserialization RCE - AsyncResponseService
CVE-2019-2725HIGHbajo ataqueransomware23 abr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
Metasploit300
Spring Cloud Config Server Directory Traversal
CVE-2019-379917 abr 2019
Directory Traversal with spring-cloud-config-server
60RIESGO
abrir
Metasploit600
SmarterTools SmarterMail less than build 6985 - .NET Deserialization Remote Code Execution
CVE-2019-721417 abr 2019
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RIESGO
abrir
Metasploit300
Oracle Application Testing Suite Post-Auth DownloadServlet Directory Traversal
CVE-2019-255716 abr 2019
Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen
18RIESGO
abrir
Metasploit300
Remote Mouse RCE
CVE-2022-3365CRITICAL15 abr 2019
Emote Interactive Remote Mouse Server command injection due to weak encoding
63RIESGO
abrir
Metasploit600
Kentico CMS Staging SyncServer Unserialize Remote Command Execution
CVE-2019-10068CRITICALbajo ataque15 abr 2019
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RIESGO
abrir
Metasploit600
Mac OS X Feedback Assistant Race Condition
CVE-2019-856513 abr 2019
A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A mali
43RIESGO
abrir
Metasploit600
Mac OS X TimeMachine (tmdiagnose) Command Injection Privilege Escalation
CVE-2019-851313 abr 2019
This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to
38RIESGO
abrir
Metasploit600
Apache Tomcat CGIServlet enableCmdLineArguments Vulnerability
CVE-2019-023210 abr 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
Metasploit300
AppXSvc Hard Link Privilege Escalation
CVE-2019-0841HIGHbajo ataqueransomware09 abr 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.