Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
Aptana Jaxer 1.0.3.4547 - Local File inclusion
CVE-2019-14312webappsmultiple08 ago 2019
Aptana Jaxer 1.0.3.4547 is vulnerable to a local file inclusion vulnerability in the wikilite source code viewer. This v
43RIESGO
abrir
Exploit-DB
Adive Framework 2.0.7 - Cross-Site Request Forgery
CVE-2019-14346webappsphp08 ago 2019
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
23RIESGO
abrir
Exploit-DB
Open-School 3.0 / Community Edition 2.3 - Cross-Site Scripting
CVE-2019-14696webappsphp08 ago 2019
Open-School 3.0, and Community Edition 2.3, allows XSS via the osv/index.php?r=students/guardians/create id parameter.
43RIESGO
abrir
Exploit-DB
WordPress Plugin JoomSport 3.3 - SQL Injection
CVE-2019-14348webappsphp07 ago 2019
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via
28RIESGO
abrir
Exploit-DBVexDay Proof
macOS iMessage - Heap Overflow when Deserializing
CVE-2019-8661dosmacos05 ago 2019
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Mojave 10.14.6. A rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tika 1.15 - 1.17 - Header Command Injection (Metasploit)
CVE-2018-1335remotewindows05 ago 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Exploit-DB
SilverSHielD 6.x - Local Privilege Escalation
CVE-2019-13069localmultiple01 ago 2019
extenua SilverSHielD 6.x fails to secure its ProgramData folder, leading to a Local Privilege Escalation to SYSTEM. The
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Hyperion Planning 11.1.2.3 - XML External Entity
CVE-2019-2861webappsmultiple31 jul 2019
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported versi
23RIESGO
abrir
Exploit-DBVexDay Proof
macOS / iOS JavaScriptCore - JSValue Use-After-Free in ValueProfiles
CVE-2019-8672dosmultiple30 jul 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
28RIESGO
abrir
Exploit-DBVexDay Proof
macOS / iOS NSKeyedUnarchiver - Use-After-Free of ObjC Objects when Unarchiving OITSUIntDictionary Instances
CVE-2019-8662dosmultiple30 jul 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - NSKeyedUnarchiver Deserialization Allows file Backed NSData Objects
CVE-2019-8646dosmultiple30 jul 2019
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10.14.
28RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - Memory Corruption when Decoding NSKnownKeysDictionary1
CVE-2019-8660dosmultiple30 jul 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.4, macOS Mojave 10
28RIESGO
abrir
Exploit-DBVexDay Proof
Amcrest Cameras 2.520.AC00.18.R - Unauthenticated Audio Streaming
CVE-2019-3948webappshardware30 jul 2019
The Amcrest IP2M-841B V2.520.AC00.18.R, Dahua IPC-XXBXX V2.622.0000000.9.R, Dahua IPC HX5X3X and HX4X3X V2.800.0000008.0
28RIESGO
abrir
Exploit-DBVexDay Proof
macOS / iOS JavaScriptCore - Loop-Invariant Code Motion (LICM) Leaves Object Property Access Unguarded
CVE-2019-8671dosmultiple30 jul 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
23RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - NSArray Deserialization can Invoke Subclass that does not Retain References
CVE-2019-8647dosmultiple30 jul 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.4, tvOS 12.4, watchO
28RIESGO
abrir
Exploit-DBVexDay Proof
Schneider Electric Pelco Endura NET55XX Encoder - Authentication Bypass (Metasploit)
CVE-2019-6814remoteunix29 jul 2019
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RIESGO
abrir
Exploit-DB
WordPress Plugin Simple Membership 3.8.4 - Cross-Site Request Forgery
CVE-2019-14328webappsphp29 jul 2019
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
23RIESGO
abrir
Exploit-DBVexDay Proof
Ahsay Backup 8.1.1.50 - Insecure File Upload and Code Execution (Authenticated)
CVE-2019-10267webappsjsp26 jul 2019
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RIESGO
abrir
Exploit-DB
Moodle Filepicker 3.5.2 - Server Side Request Forgery
CVE-2018-1042webappsphp26 jul 2019
Moodle 3.x has Server Side Request Forgery in the filepicker.
28RIESGO
abrir
Exploit-DBVexDay Proof
pdfresurrect 0.15 - Buffer Overflow
CVE-2019-14267doslinux26 jul 2019
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is misha
23RIESGO
abrir
Exploit-DB
Microsoft Windows 7 build 7601 (x86) - Local Privilege Escalation
CVE-2019-1132HIGHbajo ataquelocalwindows_x8626 jul 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
71RIESGO
abrir
Exploit-DB
Ahsay Backup 7.x - 8.1.1.50 - XML External Entity Injection
CVE-2019-10266webappsjsp26 jul 2019
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL
28RIESGO
abrir
Exploit-DB
Ahsay Backup 7.x - 8.1.1.50 - Authenticated Arbitrary File Upload / Remote Code Execution (Metasploit)
CVE-2019-10267webappsjsp26 jul 2019
An insecure file upload and code execution issue was discovered in Ahsay Cloud Backup Suite 8.1.0.50. It is possible to
60RIESGO
abrir
Exploit-DBVexDay Proof
WebKit - Universal Cross-Site Scripting due to Synchronous Page Loads
CVE-2019-8649dosmultiple25 jul 2019
A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management
23RIESGO
abrir
Exploit-DB
Ovidentia 8.4.3 - Cross-Site Scripting
CVE-2019-13977webappsphp25 jul 2019
index.php in Ovidentia 8.4.3 has XSS via tg=groups, tg=maildoms&idx=create&userid=0&bgrp=y, tg=delegat, tg=site&idx=crea
23RIESGO
abrir
Exploit-DBVexDay Proof
Apple iMessage - DigitalTouch tap Message Processing Out-of-Bounds Read
CVE-2019-8624doswatchos24 jul 2019
An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 5.3. A remote attacke
23RIESGO
abrir
Exploit-DB
Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation
CVE-2019-13272HIGHbajo ataquelocallinux24 jul 2019
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a proce
98RIESGO
abrir
Exploit-DB
Cisco Wireless Controller 3.6.10E - Cross-Site Request Forgery
CVE-2019-12624HIGHwebappshardware24 jul 2019
Cisco IOS XE NGWC Legacy Wireless Device Manager GUI Cross-Site Request Forgery Vulnerability
46RIESGO
abrir
Exploit-DB
Android 7 < 9 - Remote Code Execution
CVE-2019-2107remoteandroid24 jul 2019
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RIESGO
abrir
Exploit-DB
BACnet Stack 0.8.6 - Denial of Service
CVE-2019-12480doslinux22 jul 2019
BACnet Protocol Stack through 0.8.6 has a segmentation fault leading to denial of service in BACnet APDU Layer because a
35RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.