Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
Optergy 2.3.0a - Remote Code Execution (Backdoor)
CVE-2019-7276webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RIESGO
abrir
Exploit-DB
eMerge E3 1.00-06 - Remote Code Execution
CVE-2019-7256CRITICALbajo ataquewebappshardware12 nov 2019
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir
Exploit-DB
Optergy 2.3.0a - Remote Code Execution
CVE-2019-7274webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Authenticated File Upload with Code Execution as root.
28RIESGO
abrir
Exploit-DB
Adrenalin Core HCM 5.4.0 - 'ReportID' Reflected Cross-Site Scripting
CVE-2018-12653webappsaspx12 nov 2019
A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious Jav
23RIESGO
abrir
Exploit-DB
eMerge E3 1.00-06 - Arbitrary File Upload
CVE-2019-7257webappshardware12 nov 2019
Linear eMerge E3-Series devices allow Unrestricted File Upload.
35RIESGO
abrir
Exploit-DB
FlexAir Access Control 2.3.35 - Authentication Bypass
CVE-2019-7666webappshardware12 nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. The application allows improper authentication using the MD5 hash valu
28RIESGO
abrir
Exploit-DB
Atlassian Confluence 6.15.1 - Directory Traversal
CVE-2019-3398HIGHbajo ataquewebappsjsp12 nov 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RIESGO
abrir
Exploit-DB
eMerge50P 5000P 4.6.07 - Remote Code Execution
CVE-2019-7269webappshardware12 nov 2019
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
35RIESGO
abrir
Exploit-DB
eMerge E3 1.00-06 - Privilege Escalation
CVE-2019-7254webappshardware12 nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RIESGO
abrir
Exploit-DB
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
CVE-2019-10846webappshardware12 nov 2019
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw
23RIESGO
abrir
Exploit-DB
CBAS-Web 19.0.0 - Username Enumeration
CVE-2019-10848webappshardware12 nov 2019
Computrols CBAS 18.0.0 allows Username Enumeration.
23RIESGO
abrir
Exploit-DB
Optergy 2.3.0a - Username Disclosure
CVE-2019-7272webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Username Disclosure.
28RIESGO
abrir
Exploit-DB
eMerge E3 1.00-06 - Cross-Site Request Forgery
CVE-2019-7262webappshardware12 nov 2019
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
28RIESGO
abrir
Exploit-DB
eMerge E3 1.00-06 - 'layout' Reflected Cross-Site Scripting
CVE-2019-7255webappshardware12 nov 2019
Linear eMerge E3-Series devices allow XSS.
50RIESGO
abrir
Exploit-DB
Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
CVE-2019-7671webappsalpha12 nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
23RIESGO
abrir
Exploit-DB
Prima Access Control 2.3.35 - Arbitrary File Upload
CVE-2019-9189webappshardware12 nov 2019
Prima Systems FlexAir, Versions 2.4.9api3 and prior. The application allows the upload of arbitrary Python scripts when
28RIESGO
abrir
Exploit-DB
Optergy 2.3.0a - Cross-Site Request Forgery (Add Admin)
CVE-2019-7273webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Cross-Site Request Forgery (CSRF).
23RIESGO
abrir
Exploit-DB
CBAS-Web 19.0.0 - Information Disclosure
CVE-2019-10849remotehardware12 nov 2019
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
23RIESGO
abrir
Exploit-DB
eMerge E3 1.00-06 - Unauthenticated Directory Traversal
CVE-2019-7254webappshardware12 nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8662dosmultiple11 nov 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
CVE-2019-8196doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8641dosmultiple11 nov 2019
An out-of-bounds read was addressed with improved input validation.
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8195doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir
Exploit-DBVexDay Proof
rConfig - install Command Execution (Metasploit)
CVE-2019-16662remotelinux08 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
Exploit-DB
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
CVE-2019-10475webappsjava08 nov 2019
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RIESGO
abrir
Exploit-DBVexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
CVE-2017-13156localandroid08 nov 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
Exploit-DB
Adive Framework 2.0.7 - Privilege Escalation
CVE-2019-14347webappsphp08 nov 2019
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RIESGO
abrir
Exploit-DBVexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
CVE-2019-8820dosmultiple05 nov 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus (HPE) Data Protector - SUID Privilege Escalation (Metasploit)
CVE-2019-11660locallinux04 nov 2019
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RIESGO
abrir
Exploit-DB
Apache Solr 8.2.0 - Remote Code Execution
CVE-2019-17558HIGHbajo ataquewebappsjava01 nov 2019
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.