Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
79.230 exploits
GitHub PoC
gurneesh/CVE-2019-14287-write-up
CVE-2019-1428716 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC10
Standalone Python 3 exploit for CVE-2017-17562
CVE-2017-17562HIGHbajo ataque16 oct 2019
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
GitHub PoC1
Exploit and Mass Pwn3r for CVE-2019-16920
CVE-2019-16920CRITICALbajo ataque16 oct 2019
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The i
100RIESGO
abrir
Metasploit600
Solaris xscreensaver log Privilege Escalation
CVE-2019-3010HIGHbajo ataque16 oct 2019
Vulnerability in the Oracle Solaris product of Oracle Systems (component: XScreenSaver). The supported version that is a
91RIESGO
abrir
GitHub PoC1
FauxFaux/sudo-cve-2019-14287
CVE-2019-1428715 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALbajo ataqueransomware15 oct 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware15 oct 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC13
Sudo exploit
CVE-2019-1428715 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC9
CVE-2019-16728 Proof of Concept
CVE-2019-16278CRITICALbajo ataque15 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC70
Directory transversal to remote code execution
CVE-2019-16278CRITICALbajo ataque15 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque15 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque15 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16278CRITICALbajo ataque15 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
GitHub PoC3
CVE-2019-16278Nostromo httpd命令执行
CVE-2019-16278CRITICALbajo ataque15 oct 2019
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote co
100RIESGO
abrir
Exploit-DB
sudo 1.8.27 - Security Bypass
CVE-2019-14287locallinux15 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
GitHub PoC1
This is a container built for demonstration purposes that has a version of the sudo command which is vulnerable to CVE-2019-14287
CVE-2019-1428715 oct 2019
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
Exploit-DB
Kirona-DRS 5.5.3.5 - Information Disclosure
CVE-2019-17503webappsphp14 oct 2019
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. An unauthenticated user can access /osm/REG
50RIESGO
abrir
GitHub PoC
Spring Security OAuth 2.3 Open Redirection 分析复现篇
CVE-2019-377814 oct 2019
Open Redirect in spring-security-oauth2
28RIESGO
abrir
GitHub PoC136
Temproot for Pixel 2 and Pixel 2 XL via CVE-2019-2215
CVE-2019-2215HIGHbajo ataque14 oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
Metasploit600
Ajenti auth username Command Injection
CVE-2019-25066MEDIUM14 oct 2019
ajenti API privileges management
28RIESGO
abrir
Exploit-DB
Kirona-DRS 5.5.3.5 - Information Disclosure
CVE-2019-17504webappsphp14 oct 2019
An issue was discovered in Kirona Dynamic Resource Scheduling (DRS) 5.5.3.5. A reflected Cross-site scripting (XSS) vuln
23RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque14 oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-13379CRITICALbajo ataqueransomware14 oct 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Exploit-DB
Apache Httpd mod_proxy - Error Page Cross-Site Scripting
CVE-2019-10092webappsmultiple14 oct 2019
In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page
60RIESGO
abrir
Exploit-DB
WordPress Core < 5.2.3 - Viewing Unauthenticated/Password/Private Posts
CVE-2019-17671webappsmultiple14 oct 2019
In WordPress before 5.2.4, unauthenticated viewing of certain content is possible because the static query property is m
50RIESGO
abrir
GitHub PoC12
CVE-2018-13379 Script for Nmap NSE.
CVE-2018-13379CRITICALbajo ataqueransomware14 oct 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Exploit-DB
Apache Httpd mod_rewrite - Open Redirects
CVE-2019-10098webappsmultiple14 oct 2019
In Apache HTTP server 2.4.0 to 2.4.39, Redirects configured with mod_rewrite that were intended to be self-referential m
60RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque12 oct 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALbajo ataque12 oct 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
GitHub PoC
h-wookie/cve-2019-5736-poc
CVE-2019-573612 oct 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
anteriorpágina 810 / 2641siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.