Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
79.230 exploits
Exploit-DB
Apache Solr 8.2.0 - Remote Code Execution
CVE-2019-17558HIGHbajo ataquewebappsjava01 nov 2019
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
Exploit-DBVexDay Proof
Nostromo - Directory Traversal Remote Command Execution (Metasploit)
CVE-2019-16278CRITICALbajo ataqueremotemultiple01 nov 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
Exploit-DB
MikroTik RouterOS 6.45.6 - DNS Cache Poisoning
CVE-2019-3978remotehardware31 oct 2019
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queri
28RIESGO
abrir
Exploit-DBVexDay Proof
JavaScriptCore - GetterSetter Type Confusion During DFG Compilation
CVE-2019-8765dosmultiple30 oct 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in watchOS 6.1. Proc
23RIESGO
abrir
Metasploit0
Kibana Timelion Prototype Pollution RCE
CVE-2019-7609CRITICALbajo ataque30 oct 2019
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker
100RIESGO
abrir
GitHub PoC8
Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.
CVE-2019-11043HIGHbajo ataqueransomware30 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHbajo ataqueransomware30 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
3rg1s/CVE-2016-2098
CVE-2016-209830 oct 2019
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RIESGO
abrir
GitHub PoC10
Mayter/CVE-2019-1315
CVE-2019-1315HIGHbajo ataqueransomware29 oct 2019
An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka '
71RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Remote Code Execution (MS15-011)
CVE-2015-0008remotewindows29 oct 2019
The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Wind
28RIESGO
abrir
Exploit-DB
Microsoft Windows Server 2012 - 'Group Policy' Security Feature Bypass (MS15-014)
CVE-2015-0009remotewindows29 oct 2019
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHbajo ataqueransomware29 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Metasploit600
Linear eMerge E3-Series Access Controller Command Injection
CVE-2019-7256CRITICALbajo ataque29 oct 2019
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir
Metasploit600
Apache Solr Remote Code Execution via Velocity Template
CVE-2019-17558HIGHbajo ataque29 oct 2019
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
Exploit-DB
rConfig 3.9.2 - Remote Code Execution
CVE-2019-16662webappsphp29 oct 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
GitHub PoC5
Python exp for CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware29 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Exploit-DB
PHP-FPM + Nginx - Remote Code Execution
CVE-2019-11043HIGHbajo ataqueransomwarewebappsphp28 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC1
CVE-2019-11043 PHP远程代码执行
CVE-2019-11043HIGHbajo ataqueransomware28 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC146
(PoC) Python version of CVE-2019-11043 exploit by neex
CVE-2019-11043HIGHbajo ataqueransomware28 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHbajo ataqueransomware28 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHbajo ataqueransomware28 oct 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
GitHub PoC
huang919/cve-2019-14287-PPT
CVE-2019-1428728 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
Metasploit600
rConfig install Command Execution
CVE-2019-1666228 oct 2019
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
GitHub PoC
TEST
CVE-2019-3396CRITICALbajo ataqueransomware28 oct 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC19
CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVE-2019-10149CRITICALbajo ataque27 oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC4
apache axis1.4远程代码执行漏洞
CVE-2019-022727 oct 2019
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2
45RIESGO
abrir
GitHub PoC7
FUDForum 3.0.9 - XSS / Remote Code Execution (CVE-2019-18873, CVE-2019-18839)
CVE-2019-1887327 oct 2019
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-10149CRITICALbajo ataque27 oct 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC2
CVE-2000-0979
CVE-2000-097926 oct 2019
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file
35RIESGO
abrir
Exploit-DB
ClonOs WEB UI 19.09 - Improper Access Control
CVE-2019-18418webappsphp25 oct 2019
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests be
23RIESGO
abrir
anteriorpágina 807 / 2641siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.