Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
Apache Solr 8.2.0 - Remote Code Execution
CVE-2019-17558HIGHbajo ataquewebappsjava01 nov 2019
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
Exploit-DB
MikroTik RouterOS 6.45.6 - DNS Cache Poisoning
CVE-2019-3978remotehardware31 oct 2019
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queri
28RIESGO
abrir
Exploit-DBVexDay Proof
JavaScriptCore - GetterSetter Type Confusion During DFG Compilation
CVE-2019-8765dosmultiple30 oct 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Proc
23RIESGO
abrir
Exploit-DB
rConfig 3.9.2 - Remote Code Execution
CVE-2019-16662webappsphp29 oct 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Remote Code Execution (MS15-011)
CVE-2015-0008remotewindows29 oct 2019
The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wind
28RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Security Feature Bypass (MS15-014)
CVE-2015-0009remotewindows29 oct 2019
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RIESGO
abrir
Exploit-DB
PHP-FPM + Nginx - Remote Code Execution
CVE-2019-11043HIGHbajo ataqueransomwarewebappsphp28 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Exploit-DB
ClonOs WEB UI 19.09 - Improper Access Control
CVE-2019-18418webappsphp25 oct 2019
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests be
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux Polkit - pkexec helper PTRACE_TRACEME local root (Metasploit)
CVE-2019-13272HIGHbajo ataquelocallinux24 oct 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Exploit-DB
Rocket.Chat 2.1.0 - Cross-Site Scripting
CVE-2019-17220webappslinux23 oct 2019
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
23RIESGO
abrir
Exploit-DBVexDay Proof
Total.js CMS 12 - Widget JavaScript Code Injection (Metasploit)
CVE-2019-15954remotemultiple22 oct 2019
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote
60RIESGO
abrir
Exploit-DB
Moxa EDR-810 - Command Injection / Information Disclosure
CVE-2019-10963remotehardware22 oct 2019
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from
23RIESGO
abrir
Exploit-DB
Moxa EDR-810 - Command Injection / Information Disclosure
CVE-2019-10969remotehardware22 oct 2019
Moxa EDR 810, all versions 5.1 and prior, allows an authenticated attacker to abuse the ping feature to execute unauthor
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow due to Malformed JP2 Stream (2)
CVE-2019-8197doswindows21 oct 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Anti-Threat Toolkit 1.62.0.1218 - Remote Code Execution
CVE-2019-9491localwindows21 oct 2019
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to
28RIESGO
abrir
Exploit-DB
Solaris 11.4 - xscreensaver Privilege Escalation
CVE-2019-3010HIGHbajo ataquelocalsolaris21 oct 2019
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir
Exploit-DBVexDay Proof
ThinVNC 1.0b1 - Authentication Bypass
CVE-2019-17662remotewindows17 oct 2019
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir
Exploit-DB
Whatsapp 2.19.216 - Remote Code Execution
CVE-2019-11932remoteandroid16 oct 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
Exploit-DB
sudo 1.8.27 - Security Bypass
CVE-2019-14287locallinux15 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
Exploit-DB
WordPress Core < 5.2.3 - Viewing Unauthenticated/Password/Private Posts
CVE-2019-17671webappsmultiple14 oct 2019
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m
50RIESGO
abrir
Exploit-DB
Kirona-DRS 5.5.3.5 - Information Disclosure
CVE-2019-17504webappsphp14 oct 2019
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln
23RIESGO
abrir
Exploit-DB
Kirona-DRS 5.5.3.5 - Information Disclosure
CVE-2019-17503webappsphp14 oct 2019
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REG
50RIESGO
abrir
Exploit-DB
Apache Httpd mod_rewrite - Open Redirects
CVE-2019-10098webappsmultiple14 oct 2019
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential m
60RIESGO
abrir
Exploit-DB
Apache Httpd mod_proxy - Error Page Cross-Site Scripting
CVE-2019-10092webappsmultiple14 oct 2019
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
60RIESGO
abrir
Exploit-DB
TP-Link TL-WR1043ND 2 - Authentication Bypass
CVE-2019-6971webappshardware10 oct 2019
An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packe
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - NULL Pointer Dereference in nt!MiOffsetToProtos While Parsing Malformed PE File
CVE-2019-1343doswindows10 oct 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in nt!MiParseImageLoadConfig While Parsing Malformed PE File
CVE-2019-1345doswindows10 oct 2019
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!HashKComputeFirstPageHash While Parsing Malformed PE File
CVE-2019-1346doswindows10 oct 2019
A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Servi
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - win32k.sys TTF Font Processing Pool Corruption in win32k!ulClearTypeFilter
CVE-2019-1364doswindows10 oct 2019
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - Out-of-Bounds Read in CI!CipFixImageType While Parsing Malformed PE File
CVE-2019-1344doswindows10 oct 2019
An information disclosure vulnerability exists in the way that the Windows Code Integrity Module handles objects in memo
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.