Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
Exploit-DB
WordPress Plugin WooCommerce Product Feed 2.2.18 - Cross-Site Scripting
CVE-2019-1010124webappsphp30 ago 2019
WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to
23RIESGO
abrir
Exploit-DB
Asus Precision TouchPad 11.0.0.25 - Denial of Service
CVE-2019-10709doswindows30 ago 2019
AsusPTPFilter.sys on Asus Precision TouchPad 11.0.0.25 hardware has a Pool Overflow associated with the \\.\AsusTP devic
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1837130 ago 2019
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. There is a directory traversal vulnerabilit
50RIESGO
abrir
Exploit-DB
Canon PRINT 2.5.5 - Information Disclosure
CVE-2019-14339localandroid30 ago 2019
The ContentProvider in the Canon PRINT jp.co.canon.bsd.ad.pixmaprint 2.5.5 application for Android does not properly res
23RIESGO
abrir
GitHub PoC
jason3e7/CVE-2019-11510
CVE-2019-11510CRITICALbajo ataqueransomware29 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Exploit-DBVexDay Proof
Webkit JSC: JIT - Uninitialized Variable Access in ArgumentsEliminationPhase::transform
CVE-2019-8689dosmultiple29 ago 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.4, macOS M
28RIESGO
abrir
Exploit-DB
SQLiteManager 1.2.0 / 1.2.4 - Blind SQL Injection
CVE-2019-9083webappsphp28 ago 2019
SQLiteManager 1.20 and 1.24 allows SQL injection via the /sqlitemanager/main.php dbsel parameter. NOTE: This product is
28RIESGO
abrir
Exploit-DBVexDay Proof
Tableau - XML External Entity
CVE-2019-15637HIGHwebappsmultiple27 ago 2019
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat
46RIESGO
abrir
GitHub PoC52
SSL VPN Rce
CVE-2019-11510CRITICALbajo ataqueransomware27 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC18
Nmap NSE script to detect Pulse Secure SSL VPN file disclosure CVE-2019-11510
CVE-2019-11510CRITICALbajo ataqueransomware27 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-11510CRITICALbajo ataqueransomware27 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11510CRITICALbajo ataqueransomware27 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-11510CRITICALbajo ataqueransomware26 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Exploit-DBVexDay Proof
Exim 4.87 / 4.91 - Local Privilege Escalation (Metasploit)
CVE-2019-10149CRITICALbajo ataquelocallinux26 ago 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC5
PoC for CVE-2019-11510 | Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure vulnerability
CVE-2019-11510CRITICALbajo ataqueransomware26 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Exploit-DB
WordPress Plugin Import Export WordPress Users 1.3.1 - CSV Injection
CVE-2019-15092webappsphp26 ago 2019
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - SET_REPARSE_POINT_EX Mount Point Security Feature Bypass
CVE-2019-1170HIGHlocalwindows26 ago 2019
Windows NTFS Elevation of Privilege Vulnerability
41RIESGO
abrir
Exploit-DB
openITCOCKPIT 3.6.1-2 - Cross-Site Request Forgery
CVE-2019-10227webappsphp26 ago 2019
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
23RIESGO
abrir
GitHub PoC11
A collection of tools for the Janus exploit [CVE-2017-13156].
CVE-2017-1315625 ago 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
GitHub PoC3
OpenSSH Username Enumeration - CVE-2016-6210
CVE-2016-6210MEDIUM25 ago 2019
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RIESGO
abrir
GitHub PoC8
The official exploit code for FusionPBX v4.4.8 Remote Code Execution CVE-2019-15029
CVE-2019-1502924 ago 2019
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service
28RIESGO
abrir
GitHub PoC11
The official exploit code for Centreon v19.04 Remote Code Execution CVE-2019-13024
CVE-2019-1302424 ago 2019
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitra
35RIESGO
abrir
Exploit-DB
Nimble Streamer 3.0.2-2 < 3.5.4-9 - Directory Traversal
CVE-2019-11013webappsmultiple23 ago 2019
Nimble Streamer 3.0.2-2 through 3.5.4-9 has a ../ directory traversal vulnerability. Successful exploitation could allow
43RIESGO
abrir
GitHub PoC5
CVE-2019-15107 webmin python3
CVE-2019-15107CRITICALbajo ataqueransomware23 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC52
WebLogic Insecure Deserialization - CVE-2019-2725 payload builder & exploit
CVE-2019-2725HIGHbajo ataqueransomware23 ago 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-2725HIGHbajo ataqueransomware23 ago 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware23 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware22 ago 2019
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11510CRITICALbajo ataqueransomware22 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware22 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
anteriorpágina 819 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.