Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
79.212 exploits
GitHub PoC1
CVE-2018-9995 POC
CVE-2018-999516 dic 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-999516 dic 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
Exploit-DBVexDay Proof
Linux 5.3 - Privilege Escalation via io_uring Offload of sendmsg() onto Kernel Thread with Kernel Creds
CVE-2019-19241locallinux16 dic 2019
In the Linux kernel before 5.4.2, the io_uring feature leads to requests that inadvertently have UID 0 and full capabili
23RIESGO
abrir
Exploit-DB
Roxy Fileman 1.4.5 - Directory Traversal
CVE-2019-19731webappsaspx16 dic 2019
Roxy Fileman 1.4.5 for .NET is vulnerable to path traversal. A remote attacker can write uploaded files to arbitrary loc
28RIESGO
abrir
GitHub PoC6
SmoZy92/CVE-2019-11932
CVE-2019-1193215 dic 2019
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC
ianxtianxt/CVE-2019-15107
CVE-2019-15107CRITICALbajo ataqueransomware15 dic 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-15107CRITICALbajo ataqueransomware15 dic 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-19356HIGHbajo ataque12 dic 2019
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-18935CRITICALbajo ataqueransomware12 dic 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
Metasploit300
TVT NVMS-1000 Directory Traversal
CVE-2019-20085HIGHbajo ataque12 dic 2019
TVT NVMS-1000 devices allow GET /.. Directory Traversal
100RIESGO
abrir
GitHub PoC
For test
CVE-2019-3396CRITICALbajo ataqueransomware12 dic 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC5
Netis router RCE exploit ( CVE-2019-19356)
CVE-2019-19356HIGHbajo ataque12 dic 2019
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page.
76RIESGO
abrir
GitHub PoC
CVE-2019-2725-POC
CVE-2019-2725HIGHbajo ataqueransomware12 dic 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC3
Code sample for using exploit CVE-2019-5736 to mine bitcoin with no association to original container or user.
CVE-2019-573612 dic 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-2725HIGHbajo ataqueransomware12 dic 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
Exploit-DB
Lenovo Power Management Driver 1.67.17.48 - 'pmdrvs.sys' Denial of Service (PoC)
CVE-2019-6192MEDIUMdoswindows12 dic 2019
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a
33RIESGO
abrir
GitHub PoC374
RCE exploit for a .NET JSON deserialization vulnerability in Telerik UI for ASP.NET AJAX.
CVE-2019-18935CRITICALbajo ataqueransomware12 dic 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
Exploit-DB
Apache Olingo OData 4.0 - XML External Entity Injection
CVE-2019-17554webappsjava11 dic 2019
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resoluti
28RIESGO
abrir
Exploit-DB
AppXSvc 17763 - Arbitrary File Overwrite (DoS)
CVE-2019-1476doswindows11 dic 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC - Heap-Based Memory Corruption due to Malformed TTF Font
CVE-2019-16451doswindows11 dic 2019
Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier v
35RIESGO
abrir
Metasploit600
OpenBSD Dynamic Loader chpass Privilege Escalation
CVE-2019-1972611 dic 2019
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir
Metasploit300
Microsoft Windows Uninitialized Variable Local Privilege Elevation
CVE-2019-1458HIGHbajo ataqueransomware10 dic 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC
CVE-2014-1322 - IPC Local Security Bypass | Mac OSX (Affected. >= 10.9.2)
CVE-2014-132210 dic 2019
The kernel in Apple OS X through 10.9.2 places a kernel pointer into an XNU object data structure accessible from user s
23RIESGO
abrir
GitHub PoC30
详解 k8gege的SharePoint RCE exploit cve-2019-0604-exp.py的代码,动手制作自己的payload
CVE-2019-0604CRITICALbajo ataqueransomware10 dic 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
Metasploit600
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
CVE-2017-11317CRITICALbajo ataque09 dic 2019
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir
Metasploit600
Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization
CVE-2019-18935CRITICALbajo ataqueransomware09 dic 2019
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC1
FreePBX exploit <= 2.8.0
CVE-2010-349009 dic 2019
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RIESGO
abrir
GitHub PoC1
CVE-2008-1611 TFTP 1.41 buffer overflow exploit in the filepath
CVE-2008-161108 dic 2019
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or ex
50RIESGO
abrir
Exploit-DB
Mozilla FireFox (Windows 10 x64) - Full Chain Client Side Attack
CVE-2019-11708CRITICALbajo ataquelocalwindows_x86-6407 dic 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RIESGO
abrir
GitHub PoC9
Automated script for Pulse Secure SSL VPN exploit (CVE-2019-11510) using hosts retrieved from Shodan API. You must have a Shodan account to use this script.
CVE-2019-11510CRITICALbajo ataqueransomware07 dic 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
anteriorpágina 800 / 2641siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.