Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
HPE Intelligent Management Center < 7.3 E0506P09 - Information Disclosure
CVE-2019-5392remotewatchos23 sep 2019
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RIESGO
abrir
Exploit-DB
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
CVE-2019-8605HIGHbajo ataquelocalios23 sep 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RIESGO
abrir
Exploit-DB
Gila CMS < 1.11.1 - Local File Inclusion
CVE-2019-16679webappsmultiple23 sep 2019
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
23RIESGO
abrir
Exploit-DB
vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution
CVE-2019-16759CRITICALbajo ataquewebappsphp23 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Exploit-DB
LayerBB < 1.1.4 - Cross-Site Request Forgery
CVE-2019-16531webappsphp20 sep 2019
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
23RIESGO
abrir
Exploit-DB
Western Digital My Book World II NAS 1.02.12 - Authentication Bypass / Command Execution
CVE-2019-16399webappshardware19 sep 2019
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to acce
23RIESGO
abrir
Exploit-DB
Counter-Strike Global Offensive 1.37.1.1 - 'vphysics.dll' Denial of Service (PoC)
CVE-2019-15943doswindows18 sep 2019
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or de
23RIESGO
abrir
Exploit-DB
Notepad++ < 7.7 (x64) - Denial of Service
CVE-2019-16294doswindows_x86-6416 sep 2019
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch
23RIESGO
abrir
Exploit-DB
AppXSvc - Privilege Escalation
CVE-2019-1253HIGHbajo ataqueransomwarelocalwindows16 sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir
Exploit-DB
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
CVE-2016-10258webappscfm16 sep 2019
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A
23RIESGO
abrir
Exploit-DB
Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
CVE-2019-16197webappsphp13 sep 2019
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document
23RIESGO
abrir
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16173webappsphp13 sep 2019
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
23RIESGO
abrir
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16172webappsphp13 sep 2019
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite - Invalid Read in SplicePixel While Processing OTF Fonts
CVE-2019-1245doswindows12 sep 2019
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite - Out-of-Bounds Read in sfac_GetSbitBitmap While Processing TTF Fonts
CVE-2019-1244doswindows12 sep 2019
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RIESGO
abrir
Exploit-DBVexDay Proof
October CMS - Upload Protection Bypass Code Execution (Metasploit)
CVE-2017-1000119remotephp10 sep 2019
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise
50RIESGO
abrir
Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting
CVE-2019-16117webappsphp10 sep 2019
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi
23RIESGO
abrir
Exploit-DBVexDay Proof
LibreNMS - Collectd Command Injection (Metasploit)
CVE-2019-10669remotelinux10 sep 2019
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev
60RIESGO
abrir
Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - SQL Injection
CVE-2019-16119webappsphp10 sep 2019
SQL injection in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via the admin/control
28RIESGO
abrir
Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2)
CVE-2019-16118webappsphp10 sep 2019
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi
23RIESGO
abrir
Exploit-DB
Enigma NMS 65.0.0 - OS Command Injection
CVE-2019-16072webappsmultiple09 sep 2019
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows
43RIESGO
abrir
Exploit-DB
Enigma NMS 65.0.0 - SQL Injection
CVE-2019-16065webappsmultiple09 sep 2019
A remote SQL injection web vulnerability was discovered in the Enigma NMS 65.0.0 and prior web application that allows a
23RIESGO
abrir
Exploit-DB
Enigma NMS 65.0.0 - Cross-Site Request Forgery
CVE-2019-16068webappsmultiple09 sep 2019
A CSRF vulnerability exists in NETSAS ENIGMA NMS version 65.0.0 and prior that could allow an attacker to be able to tri
23RIESGO
abrir
Exploit-DB
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Remote Code Execution
CVE-2019-11539HIGHbajo ataqueransomwareremotemultiple06 sep 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir
Exploit-DB
FusionPBX 4.4.8 - Remote Code Execution
CVE-2019-15029remotelinux06 sep 2019
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service
28RIESGO
abrir
Exploit-DBVexDay Proof
AwindInc SNMP Service - Command Injection (Metasploit)
CVE-2017-16709remotelinux05 sep 2019
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote
60RIESGO
abrir
Exploit-DB
WordPress Plugin Download Manager 2.9.93 - Cross-Site Scripting
CVE-2019-15889MEDIUMwebappsphp04 sep 2019
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by t
53RIESGO
abrir
Exploit-DB
DASAN Zhone ZNID GPON 2426A EU - Multiple Cross-Site Scripting
CVE-2019-10677webappshardware04 sep 2019
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devic
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1622MEDIUMremotejava03 sep 2019
Cisco Data Center Network Manager Information Disclosure Vulnerability
70RIESGO
abrir
Exploit-DBVexDay Proof
Cisco RV110W/RV130(W)/RV215W Routers Management Interface - Remote Command Execution (Metasploit)
CVE-2019-1663CRITICALremotehardware03 sep 2019
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.