Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
GitHub PoC6
infiniti-team/CVE-2019-0708
CVE-2019-0708CRITICALbajo ataqueransomware29 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Exploit-DBVexDay Proof
Qualcomm Android - Kernel Use-After-Free via Incorrect set_page_dirty() in KGSL
CVE-2019-10529dosandroid29 may 2019
Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set
23RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2019-0708CRITICALbajo ataqueransomware29 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-999528 may 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC5
基于360公开的无损检测工具的可直接在windows上运行的批量检测程序
CVE-2019-0708CRITICALbajo ataqueransomware28 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Exploit-DB
Petraware pTransformer ADC < 2.1.7.22827 - Login Bypass
CVE-2019-12372remotewindows28 may 2019
Petraware pTransformer ADC before 2.1.7.22827 allows SQL Injection via the User ID parameter to the login form.
23RIESGO
abrir
GitHub PoC
ABIZCHI/CVE-2018-9995_dvr_credentials
CVE-2018-999528 may 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
GitHub PoC127
Only Hitting PoC [Tested on Windows Server 2008 r2]
CVE-2019-0708CRITICALbajo ataqueransomware28 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
caxmd/CVE-2017-13156
CVE-2017-1315627 may 2019
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2013-015627 may 2019
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-6340HIGHbajo ataque27 may 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
GitHub PoC2
aenlr/strutt-cve-2014-0114
CVE-2014-011427 may 2019
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RIESGO
abrir
Exploit-DB
Typora 0.9.9.24.6 - Directory Traversal
CVE-2019-12137remotemacos27 may 2019
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substr
23RIESGO
abrir
GitHub PoC71
Drupal8's REST RCE, SA-CORE-2019-003, CVE-2019-6340
CVE-2019-6340HIGHbajo ataque27 may 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
Exploit-DB
Deltek Maconomy 2.2.5 - Local File Inclusion
CVE-2019-12314webappsmultiple27 may 2019
Deltek Maconomy 2.2.5 is prone to local file inclusion via absolute path traversal in the WS.macx1.W_MCS/ PATH_INFO, as
60RIESGO
abrir
GitHub PoC
Arbitrary deserialization that can be used to trigger SQL injection and even Code execution
CVE-2013-015627 may 2019
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RIESGO
abrir
GitHub PoC6
Mass MikroTik WinBox Exploitation tool, CVE-2018-14847
CVE-2018-14847CRITICALbajo ataque26 may 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-14847CRITICALbajo ataque26 may 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC
yehnah
CVE-2017-8759HIGHbajo ataque24 may 2019
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8759HIGHbajo ataque24 may 2019
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer Windows 10 1809 17763.316 - Scripting Engine Memory Corruption
CVE-2019-0752HIGHbajo ataqueransomwareremotewindows24 may 2019
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
GitHub PoC
50 first stargazers will get get the tool via email
CVE-2019-0708CRITICALbajo ataqueransomware24 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC13
cve-2019-0708 poc .
CVE-2019-0708CRITICALbajo ataqueransomware24 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC920
A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.
CVE-2019-0708CRITICALbajo ataqueransomware23 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Exploit-DB
Microsoft Windows - AppX Deployment Service Local Privilege Escalation (2)
CVE-2019-0841HIGHbajo ataqueransomwarelocalwindows23 may 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
GitHub PoC2
Working proof of concept for CVE-2019-0708, spawns remote shell.
CVE-2019-0708CRITICALbajo ataqueransomware23 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC
CVE-2019-0708 PoC Exploit
CVE-2019-0708CRITICALbajo ataqueransomware23 may 2019
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC3
CVE-2019-12460|Reflected XSS in WebPort-v1.19.1 impacts users who open a maliciously crafted link or third-party web page.
CVE-2019-1246023 may 2019
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
23RIESGO
abrir
GitHub PoC3
cyy95/CVE-2019-0232-EXP
CVE-2019-023223 may 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
Exploit-DBVexDay Proof
Shopware - createInstanceFromNamedArguments PHP Object Instantiation Remote Code Execution (Metasploit)
CVE-2017-18357remotephp23 may 2019
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t
43RIESGO
abrir
anteriorpágina 833 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.