Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
GitHub PoC
Escape from Docker using CVE-2017-1000112 and CVE-2017-18344, including gaining root privilage, get all capbilities, namespace recovery, filesystem recovery, cgroup limitation bypass and seccomp bypass.
CVE-2017-100011217 sep 2019
Linux kernel: Exploitable memory corruption due to UFO to non-UFO path switch. When building a UFO packet with MSG_MORE
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALbajo ataqueransomware17 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3929CRITICALbajo ataque17 sep 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir
Exploit-DB
Symantec Advanced Secure Gateway (ASG) / ProxySG - Unrestricted File Upload
CVE-2016-10258webappscfm16 sep 2019
Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-1261316 sep 2019
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-845116 sep 2019
The /plugins/servlet/gadgets/makeRequest resource in Jira before version 8.4.0 allows remote attackers to access the con
60RIESGO
abrir
GitHub PoC4
Modified standalone exploit ported for Python 3
CVE-2018-1261316 sep 2019
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
Exploit-DB
Notepad++ < 7.7 (x64) - Denial of Service
CVE-2019-16294doswindows_x86-6416 sep 2019
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode ch
23RIESGO
abrir
Exploit-DB
AppXSvc - Privilege Escalation
CVE-2019-1253HIGHbajo ataqueransomwarelocalwindows16 sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir
GitHub PoC
Tool to exploit CVE-2018-7284 and CVE-2018-19278
CVE-2018-728415 sep 2019
A Buffer Overflow issue was discovered in Asterisk through 13.19.1, 14.x through 14.7.5, and 15.x through 15.2.1, and Ce
35RIESGO
abrir
GitHub PoC3
CVE-2019-0604: SharePoint RCE detection rules and sample PCAP
CVE-2019-0604CRITICALbajo ataqueransomware15 sep 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16172webappsphp13 sep 2019
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RIESGO
abrir
Metasploit600
Micro Focus (HPE) Data Protector SUID Privilege Escalation
CVE-2019-1166013 sep 2019
Privileges manipulation in Micro Focus Data Protector, versions 10.00, 10.01, 10.02, 10.03, 10.04, 10.10, 10.20, 10.30,
38RIESGO
abrir
Exploit-DB
Dolibarr ERP-CRM 10.0.1 - 'User-Agent' Cross-Site Scripting
CVE-2019-16197webappsphp13 sep 2019
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document
23RIESGO
abrir
Exploit-DBVexDay Proof
LimeSurvey 3.17.13 - Cross-Site Scripting
CVE-2019-16173webappsphp13 sep 2019
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite - Invalid Read in SplicePixel While Processing OTF Fonts
CVE-2019-1245doswindows12 sep 2019
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite - Out-of-Bounds Read in sfac_GetSbitBitmap While Processing TTF Fonts
CVE-2019-1244doswindows12 sep 2019
An information disclosure vulnerability exists when DirectWrite improperly discloses the contents of its memory, aka 'Di
28RIESGO
abrir
GitHub PoC19
AppXSvc Arbitrary File Security Descriptor Overwrite EoP
CVE-2019-1253HIGHbajo ataqueransomware11 sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir
GitHub PoC1
CVE-2019-0708 C#验证漏洞
CVE-2019-0708CRITICALbajo ataqueransomware11 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
likekabin/CVE-2019-1253
CVE-2019-1253HIGHbajo ataqueransomware11 sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir
GitHub PoC152
Poc for CVE-2019-1253
CVE-2019-1253HIGHbajo ataqueransomware11 sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALbajo ataqueransomware11 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-1253HIGHbajo ataqueransomware11 sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir
VulnCheck XDB
local
CVE-2019-1253HIGHbajo ataqueransomware11 sep 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir
GitHub PoC1
distance-vector/CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware11 sep 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-1609810 sep 2019
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user t
28RIESGO
abrir
Exploit-DB
WordPress Plugin Photo Gallery 1.5.34 - Cross-Site Scripting (2)
CVE-2019-16118webappsphp10 sep 2019
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi
23RIESGO
abrir
Exploit-DBVexDay Proof
October CMS - Upload Protection Bypass Code Execution (Metasploit)
CVE-2017-1000119remotephp10 sep 2019
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise
50RIESGO
abrir
GitHub PoC63
securifera/CVE-2019-1579
CVE-2019-1579HIGHbajo ataqueransomware10 sep 2019
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1579HIGHbajo ataqueransomware10 sep 2019
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RIESGO
abrir
anteriorpágina 816 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.