Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
GitHub PoC20
CVE-2019-16759 vbulletin 5.0.0 till 5.5.4 pre-auth rce
CVE-2019-16759CRITICALbajo ataque02 oct 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0145HIGHbajo ataqueransomwareremotewindows02 oct 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DBVexDay Proof
DOUBLEPULSAR - Payload Execution and Neutralization (Metasploit)
CVE-2017-0144HIGHbajo ataqueransomwareremotewindows02 oct 2019
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Exploit-DB
DotNetNuke < 9.4.0 - Cross-Site Scripting
CVE-2019-12562webappsmultiple01 oct 2019
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the mali
23RIESGO
abrir
GitHub PoC245
ispy V1.0 - Eternalblue(ms17-010)/Bluekeep(CVE-2019-0708) Scanner and exploit ( Metasploit automation )
CVE-2019-0708CRITICALbajo ataqueransomware30 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Exploit-DB
Cisco Small Business 220 Series - Multiple Vulnerabilities
CVE-2019-1913CRITICALremotehardware30 sep 2019
Cisco Small Business 220 Series Smart Switches Remote Code Execution Vulnerabilities
53RIESGO
abrir
Exploit-DB
Cisco Small Business 220 Series - Multiple Vulnerabilities
CVE-2019-1912CRITICALremotehardware30 sep 2019
Cisco Small Business 220 Series Smart Switches Authentication Bypass Vulnerability
53RIESGO
abrir
Exploit-DB
vBulletin 5.x - Remote Command Execution (Metasploit)
CVE-2019-16759CRITICALbajo ataquewebappsphp30 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Exploit-DB
Cisco Small Business 220 Series - Multiple Vulnerabilities
CVE-2019-1914HIGHremotehardware30 sep 2019
Cisco Small Business 220 Series Smart Switches Command Injection Vulnerability
46RIESGO
abrir
Exploit-DB
WordPress Plugin ARforms 3.7.1 - Arbitrary File Deletion
CVE-2019-16902webappsphp30 sep 2019
In the ARforms plugin 3.7.1 for WordPress, arf_delete_file in arformcontroller.php allows unauthenticated deletion of an
23RIESGO
abrir
Exploit-DB
GoAhead 2.5.0 - Host Header Injection
CVE-2019-16645remotemultiple30 sep 2019
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) cre
23RIESGO
abrir
Exploit-DB
phpIPAM 1.4 - SQL Injection
CVE-2019-16692webappsphp30 sep 2019
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RIESGO
abrir
GitHub PoC
A simple exploit for CVE-2007-2447
CVE-2007-244730 sep 2019
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-11708CRITICALbajo ataque29 sep 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALbajo ataque29 sep 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-981029 sep 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RIESGO
abrir
GitHub PoC624
Full exploit chain (CVE-2019-11708 & CVE-2019-9810) against Firefox on Windows 64-bit.
CVE-2019-11708CRITICALbajo ataque29 sep 2019
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result
90RIESGO
abrir
GitHub PoC21
PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script
CVE-2018-14847CRITICALbajo ataque29 sep 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC75
it works on xp (all version sp2 sp3)
CVE-2019-0708CRITICALbajo ataqueransomware29 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-845128 sep 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RIESGO
abrir
GitHub PoC5
Exploit code for CVE-2019-16692
CVE-2019-1669227 sep 2019
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is us
28RIESGO
abrir
GitHub PoC21
vBulletin 5.x 未授权远程代码执行漏洞
CVE-2019-16759CRITICALbajo ataque26 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
GitHub PoC3
Nmap NSE Script to Detect vBulletin pre-auth 5.x RCE CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque26 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALbajo ataque26 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-845126 sep 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-16759CRITICALbajo ataque26 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Metasploit600
Android Binder Use-After-Free Exploit
CVE-2019-2215HIGHbajo ataque26 sep 2019
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
Exploit-DB
Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting
CVE-2019-1262webappsaspx25 sep 2019
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
23RIESGO
abrir
Exploit-DB
NPMJS gitlabhook 0.0.17 - 'repository' Remote Command Execution
CVE-2019-5485webappsjson25 sep 2019
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje
35RIESGO
abrir
GitHub PoC5
Vbulletin rce exploit CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque25 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
anteriorpágina 814 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.