Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
VulnCheck XDB
initial-access
CVE-2019-11581CRITICALbajo ataque16 jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 < build 17763 - AppXSvc Hard Link Privilege Escalation (Metasploit)
CVE-2019-0841HIGHbajo ataqueransomwarelocalwindows16 jul 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2018-15133HIGHbajo ataqueremotelinux16 jul 2019
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
Exploit-DB
DameWare Remote Support 12.0.0.509 - 'Host' Buffer Overflow (SEH)
CVE-2018-12897localwindows16 jul 2019
SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
23RIESGO
abrir
Exploit-DB
CentOS Control Web Panel 0.9.8.838 - User Enumeration
CVE-2019-13383webappslinux16 jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.846, the Login process allows attackers to check whether a usern
28RIESGO
abrir
Exploit-DB
CentOS Control Web Panel 0.9.8.836 - Privilege Escalation
CVE-2019-13359webappslinux16 jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and uploa
28RIESGO
abrir
GitHub PoC92
Atlassian JIRA Template injection vulnerability RCE
CVE-2019-11581CRITICALbajo ataque16 jul 2019
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators an
100RIESGO
abrir
Exploit-DB
CentOS Control Web Panel 0.9.8.836 - Authentication Bypass
CVE-2019-13360webappslinux16 jul 2019
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login pro
28RIESGO
abrir
Exploit-DBVexDay Proof
PHP Laravel Framework 5.5.40 / 5.6.x < 5.6.30 - token Unserialize Remote Command Execution (Metasploit)
CVE-2017-16894remotelinux16 jul 2019
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RIESGO
abrir
Exploit-DB
Android 7 - 9 VideoPlayer - 'ihevcd_parse_pps' Out-of-Bounds Write
CVE-2019-2107dosandroid15 jul 2019
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RIESGO
abrir
Exploit-DB
FlightPath < 4.8.2 / < 5.0-rc2 - Local File Inclusion
CVE-2019-13396webappsphp15 jul 2019
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an in
50RIESGO
abrir
Exploit-DB
CISCO Small Business 200 / 300 / 500 Switches - Multiple Vulnerabilities
CVE-2019-1943MEDIUMwebappshardware15 jul 2019
Cisco Small Business Series Switches Open Redirect Vulnerability
48RIESGO
abrir
GitHub PoC
Proof of concept tool to exploit the directory traversal and local file inclusion vulnerability that resides in the Sahi-pro web application CVE-2019-13063
CVE-2019-1306315 jul 2019
Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc
28RIESGO
abrir
Exploit-DB
Microsoft Windows Remote Desktop - 'BlueKeep' Denial of Service (Metasploit)
CVE-2019-0708CRITICALbajo ataqueransomwaredoswindows15 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Metasploit600
LibreNMS Collectd Command Injection
CVE-2019-1066915 jul 2019
An issue was discovered in LibreNMS through 1.47. There is a command injection vulnerability in html/includes/graphs/dev
60RIESGO
abrir
GitHub PoC23
Metasploit module for massive Denial of Service using #Bluekeep vector.
CVE-2019-0708CRITICALbajo ataqueransomware14 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALbajo ataqueransomware14 jul 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC1
CVE-2019-9766 React
CVE-2019-976614 jul 2019
Stack-based buffer overflow in Free MP3 CD Ripper 2.6, when converting a file, allows user-assisted remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
Xymon 4.3.25 - useradm Command Execution (Metasploit)
CVE-2016-2056remotemultiple12 jul 2019
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via
50RIESGO
abrir
GitHub PoC4
R/W
CVE-2019-053912 jul 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
Exploit-DB
Jenkins Dependency Graph View Plugin 0.13 - Persistent Cross-Site Scripting
CVE-2019-10349webappsjava12 jul 2019
A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12989CRITICALbajo ataquewebappscgi12 jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10.0.17134.648 - HTTP -> SMB NTLM Reflection Leads to Privilege Elevation
CVE-2019-1019HIGHlocalwindows12 jul 2019
Microsoft Windows Security Feature Bypass Vulnerability
46RIESGO
abrir
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12991HIGHbajo ataquewebappscgi12 jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of
93RIESGO
abrir
Exploit-DB
SNMPc Enterprise Edition 9/10 - Mapping Filename Buffer Overflow
CVE-2019-13494localwindows11 jul 2019
nodeimp.exe in Castle Rock SNMPc before 9.0.12.1 and 10.x before 10.0.9 has a stack-based buffer overflow via a long var
23RIESGO
abrir
Exploit-DB
Sitecore 9.0 rev 171002 - Persistent Cross-Site Scripting
CVE-2019-13493webappsaspx11 jul 2019
In Sitecore 9.0 rev 171002, Persistent XSS exists in the Media Library and File Manager. An authenticated unprivileged u
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Empty ROS Strings
CVE-2019-1124doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DB
FreeBSD 12.0 - 'fd' Local Privilege Escalation
CVE-2019-5596localfreebsd10 jul 2019
In FreeBSD 11.2-STABLE after r338618 and before r343786, 12.0-STABLE before r343781, and 12.0-RELEASE before 12.0-RELEAS
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Unbounded iFD
CVE-2019-1121doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling due to Out-of-Bounds cubeStackDepth
CVE-2019-1117doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
anteriorpágina 826 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.