Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
79.229 exploits
Exploit-DB
Revive Adserver 4.2 - Remote Code Execution
CVE-2019-5434webappsphp03 dic 2019
An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() cal
50RIESGO
abrir
GitHub PoC21
hekadan/CVE-2019-7609
CVE-2019-7609CRITICALbajo ataque01 dic 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-7609CRITICALbajo ataque01 dic 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC1
IE7 buffer overflow through an ANI file
CVE-2007-003829 nov 2019
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2007-003829 nov 2019
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RIESGO
abrir
Metasploit300
Anviz CrossChex Buffer Overflow
CVE-2019-1251828 nov 2019
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
50RIESGO
abrir
GitHub PoC72
guest→system(UAC手动提权)
CVE-2019-1388HIGHbajo ataqueransomware27 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC4
Exploit for CVE-2017-12945.
CVE-2017-1294527 nov 2019
Insufficient validation of user-supplied input for the Solstice Pod before 2.8.4 networking configuration enables authen
28RIESGO
abrir
GitHub PoC
Exploit the dirtycow vulnerability to login as root
CVE-2016-5195HIGHbajo ataque26 nov 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque26 nov 2019
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC6
Python script to exploit RCE in Nostromo nhttpd <= 1.9.6.
CVE-2019-16278CRITICALbajo ataque26 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque26 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
Metasploit300
QNAP QTS and Photo Station Local File Inclusion
CVE-2019-7192CRITICALbajo ataqueransomware25 nov 2019
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix the
100RIESGO
abrir
Metasploit600
Liferay Portal Java Unmarshalling via JSONWS RCE
CVE-2020-7961CRITICALbajo ataque25 nov 2019
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
Metasploit300
QNAP QTS and Photo Station Local File Inclusion
CVE-2019-7195CRITICALbajo ataqueransomware25 nov 2019
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RIESGO
abrir
Metasploit300
QNAP QTS and Photo Station Local File Inclusion
CVE-2019-7194CRITICALbajo ataqueransomware25 nov 2019
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fi
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque24 nov 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2011-319224 nov 2019
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALbajo ataqueransomware24 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
crispy-peppers/Goahead-CVE-2017-17562
CVE-2017-17562HIGHbajo ataque23 nov 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
GitHub PoC
crispy-peppers/Libssh-server-CVE-2018-10933
CVE-2018-10933CRITICAL23 nov 2019
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC7
timwr/CVE-2019-5825
CVE-2019-5825MEDIUMbajo ataque23 nov 2019
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-17562HIGHbajo ataque23 nov 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-5825MEDIUMbajo ataque23 nov 2019
Out of bounds write in JavaScript in Google Chrome prior to 73.0.3683.86 allowed a remote attacker to potentially exploi
90RIESGO
abrir
GitHub PoC8
A quick python exploit for the Nostromo 1.9.6 remote code execution vulnerability. Simply takes a host and port that the web server is running on.
CVE-2019-16278CRITICALbajo ataque22 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque22 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
Exploit-DBVexDay Proof
Internet Explorer - Use-After-Free in JScript Arguments During toJSON Callback
CVE-2019-1429HIGHbajo ataquedoswindows22 nov 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALbajo ataqueransomware22 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC1
ulisesrc/-2-CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware22 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
am6539/CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware21 nov 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
anteriorpágina 802 / 2641siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.