Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
VulnCheck XDB
local
CVE-2021-3560HIGHbajo ataque27 jun 2019
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
VulnCheck XDB
local
CVE-2019-10149CRITICALbajo ataque27 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2016-1040127 jun 2019
ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access
28RIESGO
abrir
Metasploit600
Cisco Data Center Network Manager Unauthenticated Remote Code Execution
CVE-2019-1619CRITICAL26 jun 2019
Cisco Data Center Network Manager Authentication Bypass Vulnerability
85RIESGO
abrir
Metasploit600
Cisco Data Center Network Manager Unauthenticated Remote Code Execution
CVE-2019-1620CRITICAL26 jun 2019
Cisco Data Center Network Manager Arbitrary File Upload and Remote Code Execution Vulnerability
85RIESGO
abrir
Metasploit600
Cisco Data Center Network Manager Unauthenticated Remote Code Execution
CVE-2019-1622MEDIUM26 jun 2019
Cisco Data Center Network Manager Information Disclosure Vulnerability
70RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-3639MEDIUM26 jun 2019
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RIESGO
abrir
GitHub PoC99
cve-2019-0604 SharePoint RCE exploit
CVE-2019-0604CRITICALbajo ataqueransomware26 jun 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.5.6 - Magpie_debug.php Root Remote Code Execution (Metasploit)
CVE-2018-15708remotelinux26 jun 2019
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RIESGO
abrir
GitHub PoC1
spectre v4 : Speculative Store Bypass (CVE-2018-3639) proof of concept for Linux
CVE-2018-3639MEDIUM26 jun 2019
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addres
45RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.5.6 - Magpie_debug.php Root Remote Code Execution (Metasploit)
CVE-2018-15710remotelinux26 jun 2019
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RIESGO
abrir
Metasploit300
Cisco Data Center Network Manager Unauthenticated File Download
CVE-2019-1619CRITICAL26 jun 2019
Cisco Data Center Network Manager Authentication Bypass Vulnerability
85RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0604CRITICALbajo ataqueransomware26 jun 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
Metasploit300
Cisco Data Center Network Manager Unauthenticated File Download
CVE-2019-1621HIGH26 jun 2019
Cisco Data Center Network Manager Arbitrary File Download Vulnerability
41RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Spidermonkey - IonMonkey 'Array.prototype.pop' Type Confusion
CVE-2019-11707HIGHbajo ataquedosmultiple26 jun 2019
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8759HIGHbajo ataque25 jun 2019
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
GitHub PoC
CVE-2017-8759 微软word漏洞利用脚本
CVE-2017-8759HIGHbajo ataque25 jun 2019
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
Exploit-DB
SeedDMS versions < 5.1.11 - Remote Command Execution
CVE-2019-12744webappsphp24 jun 2019
SeedDMS before 5.1.11 allows Remote Command Execution (RCE) because of unvalidated file upload of PHP scripts, a differe
28RIESGO
abrir
Exploit-DB
SeedDMS < 5.1.11 - 'out.GroupMgr.php' Cross-Site Scripting
CVE-2019-12801webappsphp24 jun 2019
out/out.GroupMgr.php in SeedDMS 5.1.11 has Stored XSS by making a new group with a JavaScript payload as the "GROUP" Nam
23RIESGO
abrir
GitHub PoC14
POC CVE-2019-0708 with python script!
CVE-2019-0708CRITICALbajo ataqueransomware24 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Font Cache Service - Insecure Sections Privilege Escalation
CVE-2019-0943doswindows24 jun 2019
Windows ALPC Elevation of Privilege Vulnerability
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-1040MEDIUM24 jun 2019
Windows NTLM Tampering Vulnerability
45RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-2725HIGHbajo ataqueransomware24 jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC
Spins up an isolated test environment for experimentation with Apache Struts vulnerability CVE-2018-11776.
CVE-2018-11776HIGHbajo ataque24 jun 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
Exploit-DB
GrandNode 4.40 - Path Traversal / Arbitrary File Download
CVE-2019-12276webappsmultiple24 jun 2019
A Path Traversal vulnerability in Controllers/LetsEncryptController.cs in LetsEncryptController in GrandNode 4.40 allows
50RIESGO
abrir
Exploit-DB
SeedDMS < 5.1.11 - 'out.UsrMgr.php' Cross-Site Scripting
CVE-2019-12745webappsphp24 jun 2019
out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.
23RIESGO
abrir
Exploit-DB
dotProject 2.1.9 - SQL Injection
CVE-2019-11354webappsphp24 jun 2019
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'CmpAddRemoveContainerToCLFSLog' Arbitrary File/Directory Creation
CVE-2019-0959HIGHdoswindows24 jun 2019
Windows Common Log File System Driver Elevation of Privilege Vulnerability
41RIESGO
abrir
GitHub PoC70
Weblogic CVE-2019-2725 CVE-2019-2729 Getshell 命令执行
CVE-2019-2725HIGHbajo ataqueransomware24 jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC5
CVE-2018-17456漏洞复现(PoC+Exp)
CVE-2018-1745621 jun 2019
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir
anteriorpágina 828 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.