Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
79.230 exploits
GitHub PoC
jaychouzzk/CVE-2019-1388
CVE-2019-1388HIGHbajo ataqueransomware21 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC193
CVE-2019-1388 UAC提权 (nt authority\system)
CVE-2019-1388HIGHbajo ataqueransomware21 nov 2019
An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user
71RIESGO
abrir
GitHub PoC
am6539/CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware21 nov 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC20
CVE-2019-0232-Remote Code Execution on Apache Tomcat 7.0.42
CVE-2019-023221 nov 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
Exploit-DB
GNU Mailutils 3.7 - Privilege Escalation
CVE-2019-18862locallinux21 nov 2019
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALbajo ataqueransomware21 nov 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC1
l-iberty/cve-2012-1889
CVE-2012-1889HIGHbajo ataque20 nov 2019
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RIESGO
abrir
Exploit-DBVexDay Proof
Pulse Secure VPN - Arbitrary Command Execution (Metasploit)
CVE-2019-11539HIGHbajo ataqueransomwareremotemultiple20 nov 2019
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir
Exploit-DBVexDay Proof
Xorg X11 Server - Local Privilege Escalation (Metasploit)
CVE-2018-14665localunix20 nov 2019
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - ubuntu-aufs-modified mmap_region() Breaks Refcounting in overlayfs/shiftfs Error Path
CVE-2019-15794HIGHdoslinux20 nov 2019
Reference counting error in overlayfs/shiftfs error path when used in conjuction with aufs
41RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15792HIGHdoslinux20 nov 2019
Type confusion in shiftfs
41RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15791HIGHdoslinux20 nov 2019
Reference count underflow in shiftfs
41RIESGO
abrir
Exploit-DBVexDay Proof
FusionPBX - Operator Panel exec.php Command Execution (Metasploit)
CVE-2019-11409remotemultiple20 nov 2019
app/operator_panel/exec.php in the Operator Panel module in FusionPBX 4.4.3 suffers from a command injection vulnerabili
60RIESGO
abrir
Exploit-DBVexDay Proof
Bludit - Directory Traversal Image File Upload (Metasploit)
CVE-2019-16113remotephp20 nov 2019
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
Exploit-DBVexDay Proof
Ubuntu 19.10 - Refcount Underflow and Type Confusion in shiftfs
CVE-2019-15793MEDIUMdoslinux20 nov 2019
Mishandling of file-system uid/gid with namespaces in shiftfs
33RIESGO
abrir
Metasploit600
OpenNetAdmin Ping Command Injection
CVE-2019-25065MEDIUM19 nov 2019
OpenNetAdmin os command injection
48RIESGO
abrir
GitHub PoC5
random-robbie/CVE-2019-5418
CVE-2019-5418HIGHbajo ataque19 nov 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-11882HIGHbajo ataqueransomware19 nov 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11882HIGHbajo ataqueransomware19 nov 2019
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DB
Microsoft Windows 7 (x86) - 'BlueKeep' Remote Desktop Protocol (RDP) Remote Windows Kernel Use After Free
CVE-2019-0708CRITICALbajo ataqueransomwareremotewindows_x8619 nov 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-261819 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-289419 nov 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Su
50RIESGO
abrir
GitHub PoC52
Ladon Scanner For Python, Large Network Penetration Scanner & Cobalt Strike, vulnerability / exploit / detection / MS17010/SmbGhost/CVE-2020-0796/CVE-2018-2894
CVE-2020-0796CRITICALbajo ataqueransomware19 nov 2019
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-5418HIGHbajo ataque19 nov 2019
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir
Exploit-DB
Lexmark Services Monitor 2.27.4.0.39 - Directory Traversal
CVE-2019-16758webappshardware18 nov 2019
In Lexmark Services Monitor 2.27.4.0.39 (running on TCP port 2070), a remote attacker can use a directory traversal tech
28RIESGO
abrir
Exploit-DB
nipper-ng 0.11.10 - Remote Buffer Overflow (PoC)
CVE-2019-17424remotelinux18 nov 2019
A stack-based buffer overflow in the processPrivilage() function in IOS/process-general.c in nipper-ng 0.11.10 allows re
28RIESGO
abrir
GitHub PoC1
remote debug environment for CLion
CVE-2019-11043HIGHbajo ataqueransomware17 nov 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Exploit-DB
Microsoft Windows 10 Build 1803 < 1903 - 'COMahawk' Local Privilege Escalation
CVE-2019-1322HIGHbajo ataqueransomwarelocalwindows14 nov 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka 'Microsoft W
91RIESGO
abrir
Exploit-DB
Xfilesharing 2.5.1 - Arbitrary File Upload
CVE-2019-18951webappsphp14 nov 2019
SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files.
28RIESGO
abrir
Exploit-DB
Microsoft Windows 10 Build 1803 < 1903 - 'COMahawk' Local Privilege Escalation
CVE-2019-1405HIGHbajo ataqueransomwarelocalwindows14 nov 2019
An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly allows
91RIESGO
abrir
anteriorpágina 803 / 2641siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.