Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
GitHub PoC1
Simple Bash shell quick fix CVE-2019-10149
CVE-2019-10149CRITICALbajo ataque14 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC14
PoC for CVE-2019-10149, this vulnerability could be xploited betwen 4-87 to 4.91 version of Exim server.
CVE-2019-10149CRITICALbajo ataque13 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
Exploit-DB
Pronestor Health Monitoring < 8.1.11.0 - Privilege Escalation
CVE-2018-19113localwindows13 jun 2019
The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)
23RIESGO
abrir
GitHub PoC1
Liferay XSL - Command Execution (Metasploit)
CVE-2011-157113 jun 2019
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 G
23RIESGO
abrir
GitHub PoC1
Liferay XSL - Command Execution (Metasploit)
CVE-2011-157113 jun 2019
Unspecified vulnerability in the XSL Content portlet in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 G
23RIESGO
abrir
GitHub PoC
蓝屏poc
CVE-2019-0708CRITICALbajo ataqueransomware13 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-10149CRITICALbajo ataque13 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC
改写某大佬写的0708蓝屏脚本 改为网段批量蓝屏
CVE-2019-0708CRITICALbajo ataqueransomware13 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Exploit-DB
Sitecore 8.x - Deserialization Remote Code Execution
CVE-2019-11080webappsaspx13 jun 2019
Sitecore Experience Platform (XP) prior to 9.1.1 is vulnerable to remote code execution via deserialization, aka TFS # 2
28RIESGO
abrir
VulnCheck XDB
local
CVE-2019-1064HIGHbajo ataqueransomware12 jun 2019
Windows Elevation of Privilege Vulnerability
71RIESGO
abrir
VulnCheck XDB
local
CVE-2019-1064HIGHbajo ataqueransomware12 jun 2019
Windows Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC14
simple python socket connection to test if exim is vulnerable to CVE-2019-10149. The payload simply touch a file in /tmp/eximrce.
CVE-2019-10149CRITICALbajo ataque12 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC1
CVE-2019-0708-Msf-验证
CVE-2019-0708CRITICALbajo ataqueransomware12 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
CVE-2019-0708-RCE
CVE-2019-0708CRITICALbajo ataqueransomware12 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC7
LPE Exploit For CVE-2019-12181 (Serv-U FTP 15.1.6)
CVE-2019-1218112 jun 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir
GitHub PoC11
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHbajo ataqueransomware12 jun 2019
Windows Elevation of Privilege Vulnerability
71RIESGO
abrir
GitHub PoC26
CVE-2019-1064 Local Privilege Escalation Vulnerability
CVE-2019-1064HIGHbajo ataqueransomware12 jun 2019
Windows Elevation of Privilege Vulnerability
71RIESGO
abrir
Exploit-DB
Liferay Portal 7.1 CE GA=3 / SimpleCaptcha API - Cross-Site Scripting
CVE-2019-6588webappsjsp11 jun 2019
In Liferay Portal before 7.1 CE GA4, an XSS vulnerability exists in the SimpleCaptcha API when custom code passes unsani
23RIESGO
abrir
GitHub PoC2
welove88888/CVE-2019-2725
CVE-2019-2725HIGHbajo ataqueransomware11 jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC13
CVE-2019-0708批量检测
CVE-2019-0708CRITICALbajo ataqueransomware11 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-0841HIGHbajo ataqueransomware11 jun 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALbajo ataqueransomware11 jun 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Exploit-DB
phpMyAdmin 4.8 - Cross-Site Request Forgery
CVE-2019-12616webappsphp11 jun 2019
An issue was discovered in phpMyAdmin before 4.9.0. A vulnerability was found that allows an attacker to trigger a CSRF
28RIESGO
abrir
GitHub PoC58
A fully automatic CVE-2019-0841 bypass targeting all versions of Edge in Windows 10.
CVE-2019-0841HIGHbajo ataqueransomware11 jun 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
Exploit-DB
ProShow 9.0.3797 - Local Privilege Escalation
CVE-2019-12788localwindows11 jun 2019
An issue was discovered in Photodex ProShow Producer v9.0.3797 (an application that runs with Administrator privileges).
23RIESGO
abrir
GitHub PoC1
exploit tool of CVE-2018-10118
CVE-2018-1011810 jun 2019
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RIESGO
abrir
GitHub PoC22
quick fix for CVE-2019-10149, works on Debian\Ubuntu\Centos
CVE-2019-10149CRITICALbajo ataque10 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
GitHub PoC1
exploit tool of CVE-2018-11564
CVE-2018-1156410 jun 2019
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature.
23RIESGO
abrir
Exploit-DB
UliCMS 2019.1 'Spitting Lama' - Persistent Cross-Site Scripting
CVE-2019-11398webappsphp10 jun 2019
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitra
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-2725HIGHbajo ataqueransomware10 jun 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
anteriorpágina 830 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.