Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware22 ago 2019
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC13
Jboss Java Deserialization RCE (CVE-2017-12149)
CVE-2017-12149CRITICALbajo ataqueransomware22 ago 2019
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
GitHub PoC
Implementation of CVE-2019-15107 exploit in python
CVE-2019-15107CRITICALbajo ataqueransomware22 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC2
Dockerfiles for CVE-2019-15107(webmin RCE) recurrence including v1.890 and v1.920 with Exp for each version.
CVE-2019-15107CRITICALbajo ataqueransomware22 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC50
Pulse Secure SSL VPN pre-auth file reading
CVE-2019-11510CRITICALbajo ataqueransomware22 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC
Pulse Secure VPN CVE-2019-11510
CVE-2019-11510CRITICALbajo ataqueransomware21 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC360
Exploit for Arbitrary File Read on Pulse Secure SSL VPN (CVE-2019-11510)
CVE-2019-11510CRITICALbajo ataqueransomware21 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
GitHub PoC
CVE-2019-3396 漏洞验证txt与模板文件。
CVE-2019-3396CRITICALbajo ataqueransomware21 ago 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
Exploit-DB
LibreOffice < 6.2.6 Macro - Python Code Execution (Metasploit)
CVE-2019-9851remotemultiple21 ago 2019
LibreLogo global-event script execution
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11510CRITICALbajo ataqueransomware21 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Exploit-DB
Pulse Secure 8.1R15.1/8.2/8.3/9.0 SSL VPN - Arbitrary File Disclosure (Metasploit)
CVE-2019-11510CRITICALbajo ataqueransomwarewebappsmultiple21 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-11510CRITICALbajo ataqueransomware21 ago 2019
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
Metasploit600
Cisco UCS Director default scpuser password
CVE-2019-1935CRITICAL21 ago 2019
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
85RIESGO
abrir
Metasploit600
Cisco UCS Director Unauthenticated Remote Code Execution
CVE-2019-1937CRITICAL21 ago 2019
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass Vulnerability
85RIESGO
abrir
Metasploit600
Cisco UCS Director Unauthenticated Remote Code Execution
CVE-2019-1936HIGH21 ago 2019
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Command Injection Vulnerability
48RIESGO
abrir
Exploit-DB
QEMU - Denial of Service
CVE-2019-14378doslinux20 ago 2019
ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a cas
28RIESGO
abrir
GitHub PoC66
CVE-2019-15107 Webmin RCE (unauthorized)
CVE-2019-15107CRITICALbajo ataqueransomware19 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
Exploit-DB
Webmin 1.920 - Remote Code Execution
CVE-2019-15107CRITICALbajo ataqueransomwarewebappslinux19 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
Exploit-DB
Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Metasploit)
CVE-2018-13379CRITICALbajo ataqueransomwarewebappshardware19 ago 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Exploit-DB
Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure
CVE-2018-13379CRITICALbajo ataqueransomwarewebappshardware19 ago 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware19 ago 2019
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC4
Research Regarding CVE-2019-0708.
CVE-2019-0708CRITICALbajo ataqueransomware18 ago 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC5
Fortigate CVE-2018-13379 - Tool to search for vulnerable Fortigate hosts in Rapid7 Project Sonar data anonymously through The Tor network.
CVE-2018-13379CRITICALbajo ataqueransomware18 ago 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-13379CRITICALbajo ataqueransomware18 ago 2019
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-11707HIGHbajo ataque18 ago 2019
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
GitHub PoC42
Exploit code for CVE-2019-11707 on Firefox 66.0.3 running on Ubuntu
CVE-2019-11707HIGHbajo ataque18 ago 2019
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
GitHub PoC122
rce exploit , made to work with pocsuite3
CVE-2019-0708CRITICALbajo ataqueransomware17 ago 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALbajo ataqueransomware17 ago 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-9670CRITICALbajo ataque16 ago 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-9670CRITICALbajo ataque16 ago 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir
anteriorpágina 820 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.