Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
79.230 exploits
Exploit-DB
Atlassian Confluence 6.15.1 - Directory Traversal
CVE-2019-3398HIGHbajo ataquewebappsjsp12 nov 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RIESGO
abrir
Exploit-DB
eMerge E3 Access Controller 4.6.07 - Remote Code Execution
CVE-2019-7265remotehardware12 nov 2019
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
28RIESGO
abrir
Exploit-DB
eMerge E3 1.00-06 - Privilege Escalation
CVE-2019-7254webappshardware12 nov 2019
Linear eMerge E3-Series devices allow File Inclusion.
60RIESGO
abrir
Exploit-DB
eMerge E3 1.00-06 - Cross-Site Request Forgery
CVE-2019-7262webappshardware12 nov 2019
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
28RIESGO
abrir
Exploit-DB
Computrols CBAS-Web 19.0.0 - 'username' Reflected Cross-Site Scripting
CVE-2019-10846webappshardware12 nov 2019
Computrols CBAS 18.0.0 allows Unauthenticated Reflected Cross-Site Scripting vulnerabilities in the login page and passw
23RIESGO
abrir
Exploit-DB
CBAS-Web 19.0.0 - Information Disclosure
CVE-2019-10849remotehardware12 nov 2019
Computrols CBAS 18.0.0 allows unprotected Subversion (SVN) directory / source code disclosure.
23RIESGO
abrir
Exploit-DB
Optergy 2.3.0a - Remote Code Execution (Backdoor)
CVE-2019-7276webappshardware12 nov 2019
Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.
60RIESGO
abrir
Exploit-DB
Prima Access Control 2.3.35 - 'HwName' Persistent Cross-Site Scripting
CVE-2019-7671webappsalpha12 nov 2019
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
23RIESGO
abrir
GitHub PoC19
Suricata LUA scripts to detect CVE-2019-12255, CVE-2019-12256, CVE-2019-12258, and CVE-2019-12260
CVE-2019-1225512 nov 2019
Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TC
45RIESGO
abrir
GitHub PoC1
load-scripts.php file, which purpose is to retrieve several JavaScript packages through one single request.
CVE-2018-638911 nov 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
cve-2019-14287
CVE-2019-1428711 nov 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8641dosmultiple11 nov 2019
An out-of-bounds read was addressed with improved input validation.
28RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary can read ObjC Object at Attacker Controlled Address
CVE-2019-8662dosmultiple11 nov 2019
This issue was addressed with improved checks. This issue is fixed in iOS 12.4, macOS Mojave 10.14.6, tvOS 12.4, watchOS
23RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed OTF Font (CFF Table)
CVE-2019-8196doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader DC for Windows - Use of Uninitialized Pointer due to Malformed JBIG2Globals Stream
CVE-2019-8195doswindows11 nov 2019
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-11043HIGHbajo ataqueransomware11 nov 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC16
Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)
CVE-2019-11043HIGHbajo ataqueransomware11 nov 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC13
The official exploit for rConfig 3.9.2 Pre-auth Remote Code Execution CVE-2019-16662
CVE-2019-1666210 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1666210 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
VulnCheck XDB
local
CVE-2022-21882HIGHbajo ataqueransomware10 nov 2019
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC8
A standalone POC for CVE-2019-12840
CVE-2019-1284009 nov 2019
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
GitHub PoC1
Centreon v.19.04 Remote Code Execution exploit (CVE-2019-13024)
CVE-2019-1302408 nov 2019
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
35RIESGO
abrir
Exploit-DB
Adive Framework 2.0.7 - Privilege Escalation
CVE-2019-14347webappsphp08 nov 2019
Internal/Views/addUsers.php in Schben Adive 2.0.7 allows remote unprivileged users (editor or developer) to create an ad
23RIESGO
abrir
Exploit-DBVexDay Proof
rConfig - install Command Execution (Metasploit)
CVE-2019-16662remotelinux08 nov 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-14847CRITICALbajo ataque08 nov 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
Exploit-DB
Jenkins build-metrics plugin 1.3 - 'label' Cross-Site Scripting
CVE-2019-10475webappsjava08 nov 2019
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RIESGO
abrir
Exploit-DBVexDay Proof
Android Janus - APK Signature Bypass (Metasploit)
CVE-2017-13156localandroid08 nov 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
GitHub PoC10
Case study and POC of CVE-2017-12635: Apache CouchDB 1.7.0 / 2.x < 2.1.1 - Remote Privilege Escalation
CVE-2017-1263507 nov 2019
Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB be
60RIESGO
abrir
GitHub PoC1
phongld97/detect-cve-2018-16858
CVE-2018-16858HIGH07 nov 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir
GitHub PoC
create12138/CVE-2018-15982
CVE-2018-15982HIGHbajo ataqueransomware06 nov 2019
Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful
93RIESGO
abrir
anteriorpágina 805 / 2641siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.