Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
Verot 2.0.3 - Remote Code Execution
CVE-2019-19576webappsphp06 dic 2019
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
CVE-2019-15627localwindows06 dic 2019
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w
23RIESGO
abrir
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9022webappswindows05 dic 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
28RIESGO
abrir
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9021webappswindows05 dic 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
23RIESGO
abrir
Exploit-DB
Cisco WLC 2504 8.9 - Denial of Service (PoC)
CVE-2019-15276HIGHdoshardware04 dic 2019
Cisco Wireless LAN Controller HTTP Parsing Engine Denial of Service Vulnerability
53RIESGO
abrir
Exploit-DB
Revive Adserver 4.2 - Remote Code Execution
CVE-2019-5434webappsphp03 dic 2019
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() cal
50RIESGO
abrir
Exploit-DB
Intelbras Router RF1200 1.1.3 - Cross-Site Request Forgery
CVE-2019-19516webappshardware03 dic 2019
Intelbras WRN 150 1.0.18 devices allow CSRF via GO=system_password.asp to the goform/SysToolChangePwd URI to change a pa
23RIESGO
abrir
Exploit-DBVexDay Proof
Internet Explorer - Use-After-Free in JScript Arguments During toJSON Callback
CVE-2019-1429HIGHbajo ataquedoswindows22 nov 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
Exploit-DB
GNU Mailutils 3.7 - Privilege Escalation
CVE-2019-18862locallinux21 nov 2019
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
23RIESGO
abrir
Exploit-DBVexDay Proof
Pulse Secure VPN - Arbitrary Command Execution (Metasploit)
CVE-2019-11539HIGHbajo ataqueransomwareremotemultiple20 nov 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15792HIGHdoslinux20 nov 2019
Type confusion in shiftfs
41RIESGO
abrir
Exploit-DBVexDay Proof
FusionPBX - Operator Panel exec.php Command Execution (Metasploit)
CVE-2019-11409remotemultiple20 nov 2019
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerabili
60RIESGO
abrir
Exploit-DBVexDay Proof
Xorg X11 Server - Local Privilege Escalation (Metasploit)
CVE-2018-14665localunix20 nov 2019
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Exploit-DBVexDay Proof
Bludit - Directory Traversal Image File Upload (Metasploit)
CVE-2019-16113remotephp20 nov 2019
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15793MEDIUMdoslinux20 nov 2019
Mishandling of file-system uid/gid with namespaces in shiftfs
33RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - ubuntu-aufs-modified mmap_region() Breaks Refcounting in overlayfs/shiftfs Error Path
CVE-2019-15794HIGHdoslinux20 nov 2019
Reference counting error in overlayfs/shiftfs error path when used in conjuction with aufs
41RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15791HIGHdoslinux20 nov 2019
Reference count underflow in shiftfs
41RIESGO
abrir
Exploit-DB
Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free
CVE-2019-0708CRITICALbajo ataqueransomwareremotewindows_x8619 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Exploit-DB
nipper-ng 0.11.10 - Remote Buffer Overflow (PoC)
CVE-2019-17424remotelinux18 nov 2019
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RIESGO
abrir
Exploit-DB
Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal
CVE-2019-16758webappshardware18 nov 2019
In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal tech
28RIESGO
abrir
Exploit-DB
Microsoft Windows 10 Build 1803 < 1903 - 'COMahawk' Local Privilege Escalation
CVE-2019-1405HIGHbajo ataqueransomwarelocalwindows14 nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RIESGO
abrir
Exploit-DB
Microsoft Windows 10 Build 1803 < 1903 - 'COMahawk' Local Privilege Escalation
CVE-2019-1322HIGHbajo ataqueransomwarelocalwindows14 nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RIESGO
abrir
Exploit-DB
Xfilesharing 2.5.1 - Arbitrary File Upload
CVE-2019-18951webappsphp14 nov 2019
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
28RIESGO
abrir
Exploit-DB
FUDForum 3.0.9 - Remote Code Execution
CVE-2019-18873webappsphp13 nov 2019
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An
23RIESGO
abrir
Exploit-DB
Technicolor TD5130.2 - Remote Command Execution
CVE-2019-18396webappshardware13 nov 2019
An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Comm
28RIESGO
abrir
Exploit-DB
Prima FlexAir Access Control 2.3.38 - Remote Code Execution
CVE-2019-7670webappshardware12 nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could mo
28RIESGO
abrir
Exploit-DB
eMerge50P 5000P 4.6.07 - Remote Code Execution
CVE-2019-7269webappshardware12 nov 2019
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
35RIESGO
abrir
Exploit-DB
Atlassian Confluence 6.15.1 - Directory Traversal
CVE-2019-3398HIGHbajo ataquewebappsjsp12 nov 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RIESGO
abrir
Exploit-DB
eMerge E3 1.00-06 - Remote Code Execution
CVE-2019-7256CRITICALbajo ataquewebappshardware12 nov 2019
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir
Exploit-DB
eMerge E3 Access Controller 4.6.07 - Remote Code Execution
CVE-2019-7265remotehardware12 nov 2019
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.