Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DBVexDay Proof
ktsuss 1.4 - suid Privilege Escalation (Metasploit)
CVE-2011-2921locallinux03 sep 2019
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com
60RIESGO
abrir
Exploit-DBVexDay Proof
Cisco RV110W/RV130(W)/RV215W Routers Management Interface - Remote Command Execution (Metasploit)
CVE-2019-1663CRITICALremotehardware03 sep 2019
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1620CRITICALremotejava03 sep 2019
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
85RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Data Center Network Manager - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1622MEDIUMremotejava03 sep 2019
Cisco Data Center Network Manager Information Disclosure Vulnerability
70RIESGO
abrir
Exploit-DB
Alkacon OpenCMS 10.5.x - Cross-Site Scripting
CVE-2019-13234webappsmultiple02 sep 2019
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the search engine.
23RIESGO
abrir
Exploit-DB
Alkacon OpenCMS 10.5.x - Local File inclusion
CVE-2019-13237webappsmultiple02 sep 2019
In Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple resources vulnerable to Local File Inclusion that allow an atta
23RIESGO
abrir
Exploit-DB
Craft CMS 2.7.9/3.2.5 - Information Disclosure
CVE-2019-14280webappsphp02 sep 2019
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images whe
23RIESGO
abrir
Exploit-DB
Opencart 3.x - Cross-Site Scripting
CVE-2019-15081webappsphp02 sep 2019
OpenCart 3.x, when the attacker has login access to the admin panel, allows stored XSS within the Source/HTML editing fe
23RIESGO
abrir
Exploit-DB
Alkacon OpenCMS 10.5.x - Cross-Site Scripting (2)
CVE-2019-13236webappsmultiple02 sep 2019
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the man
23RIESGO
abrir
Exploit-DB
Alkacon OpenCMS 10.5.x - Cross-Site Scripting
CVE-2019-13235webappsmultiple02 sep 2019
In the Alkacon OpenCms Apollo Template 10.5.4 and 10.5.5, there is XSS in the Login form.
23RIESGO
abrir
Exploit-DB
Canon PRINT 2.5.5 - Information Disclosure
CVE-2019-14339localandroid30 ago 2019
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res
23RIESGO
abrir
Exploit-DB
Asus Precision TouchPad 11.0.0.25 - Denial of Service
CVE-2019-10709doswindows30 ago 2019
AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP devic
28RIESGO
abrir
Exploit-DB
WordPress Plugin WooCommerce Product Feed 2.2.18 - Cross-Site Scripting
CVE-2019-1010124webappsphp30 ago 2019
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to
23RIESGO
abrir
Exploit-DB
DomainMod 4.13 - Cross-Site Scripting
CVE-2019-15811webappsphp30 ago 2019
In DomainMOD through 4.13, the parameter daterange in the file reporting/domains/cost-by-month.php has XSS.
38RIESGO
abrir
Exploit-DBVexDay Proof
Webkit JSC: JIT - Uninitialized Variable Access in ArgumentsEliminationPhase::transform
CVE-2019-8689dosmultiple29 ago 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
28RIESGO
abrir
Exploit-DB
SQLiteManager 1.2.0 / 1.2.4 - Blind SQL Injection
CVE-2019-9083webappsphp28 ago 2019
SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is
28RIESGO
abrir
Exploit-DBVexDay Proof
Tableau - XML External Entity
CVE-2019-15637HIGHwebappsmultiple27 ago 2019
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat
46RIESGO
abrir
Exploit-DB
openITCOCKPIT 3.6.1-2 - Cross-Site Request Forgery
CVE-2019-10227webappsphp26 ago 2019
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
23RIESGO
abrir
Exploit-DB
WordPress Plugin Import Export WordPress Users 1.3.1 - CSV Injection
CVE-2019-15092webappsphp26 ago 2019
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in
23RIESGO
abrir
Exploit-DBVexDay Proof
Exim 4.87 / 4.91 - Local Privilege Escalation (Metasploit)
CVE-2019-10149CRITICALbajo ataquelocallinux26 ago 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - SET_REPARSE_POINT_EX Mount Point Security Feature Bypass
CVE-2019-1170HIGHlocalwindows26 ago 2019
Windows NTFS Elevation of Privilege Vulnerability
41RIESGO
abrir
Exploit-DB
Nimble Streamer 3.0.2-2 < 3.5.4-9 - Directory Traversal
CVE-2019-11013webappsmultiple23 ago 2019
Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow
43RIESGO
abrir
Exploit-DB
LibreOffice < 6.2.6 Macro - Python Code Execution (Metasploit)
CVE-2019-9851remotemultiple21 ago 2019
LibreLogo global-event script execution
60RIESGO
abrir
Exploit-DB
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure (Metasploit)
CVE-2019-11510CRITICALbajo ataqueransomwarewebappsmultiple21 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Exploit-DB
QEMU - Denial of Service
CVE-2019-14378doslinux20 ago 2019
ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a cas
28RIESGO
abrir
Exploit-DB
Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Metasploit)
CVE-2018-13379CRITICALbajo ataqueransomwarewebappshardware19 ago 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Exploit-DB
Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure
CVE-2018-13379CRITICALbajo ataqueransomwarewebappshardware19 ago 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Exploit-DB
Webmin 1.920 - Remote Code Execution
CVE-2019-15107CRITICALbajo ataqueransomwarewebappslinux19 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Heap-Based Buffer Overflow While Processing Malformed PDF
CVE-2019-8050doswindows15 ago 2019
Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 20
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Font Subsetting - DLL Heap Corruption in ReadAllocFormat12CharGlyphMapList
CVE-2019-1151HIGHdoswindows15 ago 2019
Microsoft Graphics Remote Code Execution Vulnerability
46RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.