Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
Metasploit600
Shopware createInstanceFromNamedArguments PHP Object Instantiation RCE
CVE-2019-12799MEDIUM09 may 2019
In createInstanceFromNamedArguments in Shopware through 5.6.x, a crafted web request can trigger a PHP object instantiat
40RIESGO
abrir
Metasploit600
Shopware createInstanceFromNamedArguments PHP Object Instantiation RCE
CVE-2017-1835709 may 2019
Shopware before 5.3.4 has a PHP Object Instantiation issue via the sort parameter to the loadPreviewAction() method of t
43RIESGO
abrir
GitHub PoC1
Docker runc CVE-2019-5736 exploit Dockerfile. Credits : https://github.com/Frichetten/CVE-2019-5736-PoC.git
CVE-2019-573609 may 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Exploit-DB
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting
CVE-2018-20485webappsphp09 may 2019
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.
23RIESGO
abrir
Exploit-DB
Zoho ManageEngine ADSelfService Plus 5.7 < 5702 build - Cross-Site Scripting
CVE-2018-20484webappsphp09 may 2019
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
23RIESGO
abrir
Exploit-DB
Lotus Domino 8.5.3 - 'EXAMINE' Stack Buffer Overflow DEP/ASLR Bypass (NSA's EMPHASISMINE)
CVE-2017-1274remotewindows08 may 2019
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Weblogic Server - 'AsyncResponseService' Deserialization Remote Code Execution (Metasploit)
CVE-2019-2725HIGHbajo ataqueransomwareremotemultiple08 may 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome 72.0.3626.119 - 'FileReader' Use-After-Free (Metasploit)
CVE-2019-5786MEDIUMbajo ataqueremotewindows_x8608 may 2019
Object lifetime issue in Blink in Google Chrome prior to 72.0.3626.121 allowed a remote attacker to potentially perform
90RIESGO
abrir
Exploit-DBVexDay Proof
PostgreSQL 9.3 - COPY FROM PROGRAM Command Execution (Metasploit)
CVE-2019-9193remotemultiple08 may 2019
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC
sasqwatch/CVE-2017-8570
CVE-2017-8570HIGHbajo ataque08 may 2019
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8570HIGHbajo ataque08 may 2019
Microsoft Office allows a remote code execution vulnerability due to the way that it handles objects in memory, aka "Mic
93RIESGO
abrir
Exploit-DB
Prinect Archive System 2015 Release 2.6 - Cross-Site Scripting
CVE-2019-10685webappsmultiple07 may 2019
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-9621HIGHbajo ataque06 may 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-9978MEDIUMbajo ataque06 may 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
Exploit-DB
LG Supersign EZ CMS - Remote Code Execution (Metasploit)
CVE-2018-17173remotehardware06 may 2019
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getT
50RIESGO
abrir
Exploit-DB
ReadyAPI 2.5.0 / 2.6.0 - Remote Code Execution
CVE-2018-20580webappsmultiple06 may 2019
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
23RIESGO
abrir
GitHub PoC79
Zimbra邮件系统漏洞 XXE/RCE/SSRF/Upload GetShell Exploit 1. (CVE-2019-9621 Zimbra<8.8.11 XXE GetShell Exploit)
CVE-2019-9621HIGHbajo ataque06 may 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RIESGO
abrir
GitHub PoC6
Wordpress Social Warfare Remote Code Execution (AUTO UPLOAD SHELL)
CVE-2019-9978MEDIUMbajo ataque06 may 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
Exploit-DB
iOS 12.1.3 - 'cfprefsd' Memory Corruption
CVE-2019-7286HIGHbajo ataquedosios06 may 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.4, macOS Mojave
76RIESGO
abrir
GitHub PoC1
cve-2019-10678
CVE-2019-1067806 may 2019
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
28RIESGO
abrir
GitHub PoC
cve-2019-9978
CVE-2019-9978MEDIUMbajo ataque06 may 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
GitHub PoC2
leerina/CVE-2019-2725
CVE-2019-2725HIGHbajo ataqueransomware05 may 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-981005 may 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALbajo ataque05 may 2019
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
GitHub PoC227
Exploit for CVE-2019-9810 Firefox on Windows 64-bit.
CVE-2019-981005 may 2019
Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check
28RIESGO
abrir
GitHub PoC2
A proof of concept for ReadyAPI 2.5.0/2.6.0 Remote Code Execution Vulnerability.
CVE-2018-2058003 may 2019
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java co
23RIESGO
abrir
Exploit-DB
SolarWinds DameWare Mini Remote Control 10.0 - Denial of Service
CVE-2019-9017doswindows03 may 2019
DWRCC in SolarWinds DameWare Mini Remote Control 10.0 x64 has a Buffer Overflow associated with the size field for the m
28RIESGO
abrir
GitHub PoC22
CVE-2019-9978 - (PoC) RCE in Social WarFare Plugin (<=3.5.2)
CVE-2019-9978MEDIUMbajo ataque03 may 2019
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_optio
100RIESGO
abrir
Exploit-DB
Crestron AM/Barco wePresent WiPG/Extron ShareLink/Teq AV IT/SHARP PN-L703WA/Optoma WPS-Pro/Blackbox HD WPS/InFocus LiteShow - Remote Command Injection
CVE-2019-3929CRITICALbajo ataquewebappshardware03 may 2019
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir
Exploit-DB
Zotonic < 0.47.0 mod_admin - Cross-Site Scripting
CVE-2019-11504webappsmultiple03 may 2019
Zotonic before version 0.47 has mod_admin XSS.
23RIESGO
abrir
anteriorpágina 838 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.