Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
piSignage 2.6.4 - Directory Traversal
CVE-2019-20354webappshardware07 ene 2020
The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)
23RIESGO
abrir
Exploit-DBVexDay Proof
nostromo 1.9.6 - Remote Code Execution
CVE-2019-16278CRITICALbajo ataqueremotemultiple01 ene 2020
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD-SA-19:02.fd - Privilege Escalation
CVE-2019-5596localfreebsd30 dic 2019
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBSD - Dynamic Loader chpass Privilege Escalation (Metasploit)
CVE-2019-19726localopenbsd30 dic 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
CVE-2019-1405HIGHbajo ataqueransomwarelocalwindows30 dic 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft UPnP - Local Privilege Elevation (Metasploit)
CVE-2019-1322HIGHbajo ataqueransomwarelocalwindows30 dic 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RIESGO
abrir
Exploit-DBVexDay Proof
Django < 3.0 < 2.2 < 1.11 - Account Hijack
CVE-2019-19844webappspython24 dic 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RIESGO
abrir
Exploit-DBVexDay Proof
OpenMRS - Java Deserialization RCE (Metasploit)
CVE-2018-19276CRITICALremotelinux18 dic 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RIESGO
abrir
Exploit-DBVexDay Proof
Linux 5.3 - Privilege Escalation via io_uring Offload of sendmsg() onto Kernel Thread with Kernel Creds
CVE-2019-19241locallinux16 dic 2019
In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBSD 6.x - Dynamic Loader Privilege Escalation
CVE-2019-19726localopenbsd16 dic 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC - Heap-Based Memory Corruption due to Malformed TTF Font
CVE-2019-16451doswindows11 dic 2019
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
35RIESGO
abrir
Exploit-DBVexDay Proof
Trend Micro Deep Security Agent 11 - Arbitrary File Overwrite
CVE-2019-15627localwindows06 dic 2019
Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, w
23RIESGO
abrir
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9022webappswindows05 dic 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
28RIESGO
abrir
Exploit-DBVexDay Proof
Broadcom CA Privilged Access Manager 2.8.2 - Remote Command Execution
CVE-2018-9021webappswindows05 dic 2019
An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to exec
23RIESGO
abrir
Exploit-DBVexDay Proof
Internet Explorer - Use-After-Free in JScript Arguments During toJSON Callback
CVE-2019-1429HIGHbajo ataquedoswindows22 nov 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
Exploit-DBVexDay Proof
Xorg X11 Server - Local Privilege Escalation (Metasploit)
CVE-2018-14665localunix20 nov 2019
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - ubuntu-aufs-modified mmap_region() Breaks Refcounting in overlayfs/shiftfs Error Path
CVE-2019-15794HIGHdoslinux20 nov 2019
Reference counting error in overlayfs/shiftfs error path when used in conjuction with aufs
41RIESGO
abrir
Exploit-DBVexDay Proof
FusionPBX - Operator Panel exec.php Command Execution (Metasploit)
CVE-2019-11409remotemultiple20 nov 2019
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerabili
60RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15792HIGHdoslinux20 nov 2019
Type confusion in shiftfs
41RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15793MEDIUMdoslinux20 nov 2019
Mishandling of file-system uid/gid with namespaces in shiftfs
33RIESGO
abrir
Exploit-DBVexDay Proof
Bludit - Directory Traversal Image File Upload (Metasploit)
CVE-2019-16113remotephp20 nov 2019
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15791HIGHdoslinux20 nov 2019
Reference count underflow in shiftfs
41RIESGO
abrir
Exploit-DBVexDay Proof
Pulse Secure VPN - Arbitrary Command Execution (Metasploit)
CVE-2019-11539HIGHbajo ataqueransomwareremotemultiple20 nov 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8641dosmultiple11 nov 2019
An out-of-bounds read was addressed with improved input validation.
28RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8662dosmultiple11 nov 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
CVE-2019-8196doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8195doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir
Exploit-DBVexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
CVE-2017-13156localandroid08 nov 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
Exploit-DBVexDay Proof
rConfig - install Command Execution (Metasploit)
CVE-2019-16662remotelinux08 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
Exploit-DBVexDay Proof
JavaScriptCore - Type Confusion During Bailout when Reconstructing Arguments Objects
CVE-2019-8820dosmultiple05 nov 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.2 and iPad
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.