Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
GitHub PoC5
Vbulletin rce exploit CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque25 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Exploit-DBVexDay Proof
ABRT - sosreport Privilege Escalation (Metasploit)
CVE-2015-5287HIGHbajo ataquelocallinux25 sep 2019
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
86RIESGO
abrir
GitHub PoC1
Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)
CVE-2018-14847CRITICALbajo ataque25 sep 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
Exploit-DB
Microsoft SharePoint 2013 SP1 - 'DestinationFolder' Persistant Cross-Site Scripting
CVE-2019-1262webappsaspx25 sep 2019
A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a speciall
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - BlueKeep RDP Remote Windows Kernel Use After Free (Metasploit)
CVE-2019-0708CRITICALbajo ataqueransomwareremotewindows24 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-13379CRITICALbajo ataqueransomware24 sep 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
GitHub PoC6
CVE-2018-13379 Exploit
CVE-2018-13379CRITICALbajo ataqueransomware24 sep 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Exploit-DBVexDay Proof
iMessage - Decoding NSSharedKeyDictionary Can Read Object Out of Bounds
CVE-2019-8641dosios24 sep 2019
An out-of-bounds read was addressed with improved input validation.
28RIESGO
abrir
GitHub PoC3
CVE-2019-1367
CVE-2019-1367HIGHbajo ataqueransomware24 sep 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
83RIESGO
abrir
Exploit-DB
Pfsense 2.3.4 / 2.4.4-p3 - Remote Code Injection
CVE-2019-16701webappsphp24 sep 2019
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_ph
28RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-845124 sep 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RIESGO
abrir
GitHub PoC10
PoC for distributed NTP reflection DoS (CVE-2013-5211)
CVE-2013-521124 sep 2019
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Metasploit300
File Sharing Wizard - POST SEH Overflow
CVE-2019-1672424 sep 2019
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2013-521124 sep 2019
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RIESGO
abrir
Exploit-DB
HPE Intelligent Management Center < 7.3 E0506P09 - Information Disclosure
CVE-2019-5392remotewatchos23 sep 2019
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RIESGO
abrir
Exploit-DB
iOS < 12.4.1 - 'Jailbreak' Local Privilege Escalation
CVE-2019-8605HIGHbajo ataquelocalios23 sep 2019
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 12.3, macOS Mojave 10.1
76RIESGO
abrir
GitHub PoC8
CVE-2018-14667-poc Richfaces漏洞环境及PoC
CVE-2018-14667CRITICALbajo ataque23 sep 2019
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
GitHub PoC1
Built a custom Virtual Machine, running Ubuntu 18.04.1 and Webmin 1.810. Using CVE-2019-15107 to exploit a backdoor in the Linux machine
CVE-2019-15107CRITICALbajo ataqueransomware23 sep 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
Exploit-DB
vBulletin 5.0 < 5.5.4 - 'widget_php ' Unauthenticated Remote Code Execution
CVE-2019-16759CRITICALbajo ataquewebappsphp23 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14667CRITICALbajo ataque23 sep 2019
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
GitHub PoC1831
Exploit for CVE-2019-11043
CVE-2019-11043HIGHbajo ataqueransomware23 sep 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Metasploit600
vBulletin widgetConfig RCE
CVE-2019-16759CRITICALbajo ataque23 sep 2019
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11043HIGHbajo ataqueransomware23 sep 2019
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
Exploit-DB
Gila CMS < 1.11.1 - Local File Inclusion
CVE-2019-16679webappsmultiple23 sep 2019
Gila CMS before 1.11.1 allows admin/fm/?f=../ directory traversal, leading to Local File Inclusion.
23RIESGO
abrir
Metasploit600
PHPStudy Backdoor Remote Code execution
CVE-2025-34061CRITICAL20 sep 2019
PHPStudy 2016-2018 Backdoor Remote Code Execution Vulnerability
63RIESGO
abrir
Exploit-DB
LayerBB < 1.1.4 - Cross-Site Request Forgery
CVE-2019-16531webappsphp20 sep 2019
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
23RIESGO
abrir
Exploit-DB
Western Digital My Book World II NAS 1.02.12 - Authentication Bypass / Command Execution
CVE-2019-16399webappshardware19 sep 2019
Western Digital WD My Book World through II 1.02.12 suffers from Broken Authentication, which allows an attacker to acce
23RIESGO
abrir
Exploit-DB
Counter-Strike Global Offensive 1.37.1.1 - 'vphysics.dll' Denial of Service (PoC)
CVE-2019-15943doswindows18 sep 2019
vphysics.dll in Counter-Strike: Global Offensive before 1.37.1.1 allows remote attackers to achieve code execution or de
23RIESGO
abrir
GitHub PoC5
Crestron/Barco/Extron/InFocus/TeqAV Remote Command Injection (CVE-2019-3929) Metasploit Module
CVE-2019-3929CRITICALbajo ataque17 sep 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3929CRITICALbajo ataque17 sep 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir
anteriorpágina 815 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.