Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
79.211 exploits
GitHub PoC4
Identify vulnerable (RCE) vBulletin 5.0.0 - 5.5.4 instances using Shodan (CVE-2019-16759)
CVE-2019-16759CRITICALbajo ataque29 dic 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
GitHub PoC5
CVE-2018-8639-EXP
CVE-2018-8639HIGHbajo ataqueransomware27 dic 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
76RIESGO
abrir
GitHub PoC
HttpFileServer httpd 2.3
CVE-2014-6287CRITICALbajo ataque27 dic 2019
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6287CRITICALbajo ataque27 dic 2019
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
GitHub PoC111
masahiro331/CVE-2019-10758
CVE-2019-10758CRITICALbajo ataque26 dic 2019
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-10758CRITICALbajo ataque26 dic 2019
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-15107CRITICALbajo ataqueransomware25 dic 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC8
PoC for CVE-2019-19844 ( https://www.djangoproject.com/weblog/2019/dec/18/security-releases/ )
CVE-2019-1984425 dic 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RIESGO
abrir
GitHub PoC8
poc exploit for webmin backdoor (CVE-2019-15107 and CVE-2019-15231)
CVE-2019-15107CRITICALbajo ataqueransomware25 dic 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC78
Apache Log4j 1.2.X存在反序列化远程代码执行漏洞
CVE-2019-17571CRITICAL25 dic 2019
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be explo
60RIESGO
abrir
Exploit-DBVexDay Proof
Django < 3.0 < 2.2 < 1.11 - Account Hijack
CVE-2019-19844webappspython24 dic 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RIESGO
abrir
Metasploit600
D-Link DIR-859 Unauthenticated Remote Command Execution
CVE-2019-17621CRITICALbajo ataque24 dic 2019
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated rem
100RIESGO
abrir
Metasploit600
D-Link Devices Unauthenticated Remote Command Execution in ssdpcgi
CVE-2019-2021524 dic 2019
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RIESGO
abrir
GitHub PoC3
CVE-2018-6389: WordPress <= 4.9.x 拒绝服务(DOS)漏洞
CVE-2018-638922 dic 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC1
my extended take on Mark Brand's CVE 2016-3861 libutils bug
CVE-2016-386121 dic 2019
LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016
23RIESGO
abrir
GitHub PoC100
PoC for CVE-2019-19844(https://www.djangoproject.com/weblog/2019/dec/18/security-releases/)
CVE-2019-1984421 dic 2019
Django before 1.11.27, 2.x before 2.2.9, and 3.x before 3.0.1 allows account takeover. A suitably crafted email address
35RIESGO
abrir
GitHub PoC644
一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
CVE-2018-595521 dic 2019
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware21 dic 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALbajo ataqueransomware20 dic 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
Mass exploit for CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware20 dic 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
local
CVE-2017-11882HIGHbajo ataqueransomware19 dic 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Metasploit600
IBM TM1 / Planning Analytics Unauthenticated Remote Code Execution
CVE-2019-4716CRITICALbajo ataque19 dic 2019
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated use
100RIESGO
abrir
Exploit-DBVexDay Proof
OpenMRS - Java Deserialization RCE (Metasploit)
CVE-2018-19276CRITICALremotelinux18 dic 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RIESGO
abrir
Exploit-DB
Telerik UI - Remote Code Execution via Insecure Deserialization
CVE-2019-18935CRITICALbajo ataqueransomwarewebappsaspx18 dic 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC5
CVE-2019-10092 Docker - Apache HTTP Server
CVE-2019-1009218 dic 2019
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
60RIESGO
abrir
Exploit-DB
Rumpus FTP Web File Manager 8.2.9.1 - Reflected Cross-Site Scripting
CVE-2019-19368webappsasp18 dic 2019
A Reflected Cross Site Scripting was discovered in the Login page of Rumpus FTP Web File Manager 8.2.9.1. An attacker ca
43RIESGO
abrir
Metasploit600
Citrix ADC (NetScaler) Directory Traversal RCE
CVE-2019-19781CRITICALbajo ataqueransomware17 dic 2019
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
Metasploit300
Citrix ADC (NetScaler) Directory Traversal Scanner
CVE-2019-19781CRITICALbajo ataqueransomware17 dic 2019
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
Exploit-DBVexDay Proof
Linux 5.3 - Privilege Escalation via io_uring Offload of sendmsg() onto Kernel Thread with Kernel Creds
CVE-2019-19241locallinux16 dic 2019
In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenBSD 6.x - Dynamic Loader Privilege Escalation
CVE-2019-19726localopenbsd16 dic 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir
anteriorpágina 799 / 2641siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.