Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
GitHub PoC15
Python script to exploit confluence path traversal vulnerability cve-2019-3398
CVE-2019-3398HIGHbajo ataque20 abr 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RIESGO
abrir
GitHub PoC
TateYdq/CVE-2018-9995-ModifiedByGwolfs
CVE-2018-999520 abr 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-3398HIGHbajo ataque20 abr 2019
Confluence Server and Data Center had a path traversal vulnerability in the downloadallattachments resource. A remote at
100RIESGO
abrir
Exploit-DBVexDay Proof
SystemTap 1.3 - MODPROBE_OPTIONS Privilege Escalation (Metasploit)
CVE-2010-4170locallinux19 abr 2019
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Business Intelligence 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - Directory Traversal
CVE-2019-2588webappswindows19 abr 2019
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
50RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Business Intelligence / XML Publisher 11.1.1.9.0 / 12.2.1.3.0 / 12.2.1.4.0 - XML External Entity Injection
CVE-2019-2616HIGHbajo ataquewebappswindows19 abr 2019
Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publi
100RIESGO
abrir
Exploit-DBVexDay Proof
Atlassian Confluence Widget Connector Macro - Velocity Template Injection (Metasploit)
CVE-2019-3396CRITICALbajo ataqueransomwareremotemultiple19 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
Exploit-DBVexDay Proof
LibreOffice < 6.0.7 / 6.1.3 - Macro Code Execution (Metasploit)
CVE-2018-16858HIGHlocalmultiple18 abr 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir
Exploit-DB
Netwide Assembler (NASM) 2.14rc15 - NULL Pointer Dereference (PoC)
CVE-2018-16517dosmultiple18 abr 2019
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a deni
23RIESGO
abrir
Exploit-DB
Evernote 7.9 - Code Execution via Path Traversal
CVE-2019-10038localmacos18 abr 2019
Evernote 7.9 on macOS allows attackers to execute arbitrary programs by embedding a reference to a local executable file
23RIESGO
abrir
Exploit-DB
ASUS HG100 - Denial of Service
CVE-2018-11492doshardware17 abr 2019
ASUS HG100 devices allow denial of service via an IPv4 packet flood.
28RIESGO
abrir
GitHub PoC31
CVE-2019-3799 - Spring Cloud Config Server: Directory Traversal < 2.1.2, 2.0.4, 1.4.6
CVE-2019-379917 abr 2019
Directory Traversal with spring-cloud-config-server
60RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Java Runtime Environment - Heap Corruption During TTF font Rendering in sc_FindExtrema4
CVE-2019-2697dosmultiple17 abr 2019
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Ja
28RIESGO
abrir
GitHub PoC
A python script that tests for an exploitable instance of CVE-2018-1235.
CVE-2018-123517 abr 2019
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command inje
35RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-261817 abr 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
35RIESGO
abrir
Metasploit300
Spring Cloud Config Server Directory Traversal
CVE-2019-379917 abr 2019
Directory Traversal with spring-cloud-config-server
60RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Java Runtime Environment - Heap Corruption During TTF font Rendering in GlyphIterator::setCurrGlyphID
CVE-2019-2698dosmultiple17 abr 2019
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Ja
28RIESGO
abrir
Metasploit600
SmarterTools SmarterMail less than build 6985 - .NET Deserialization Remote Code Execution
CVE-2019-721417 abr 2019
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RIESGO
abrir
Exploit-DB
Zoho ManageEngine ADManager Plus 6.6 (Build < 6659) - Privilege Escalation
CVE-2018-19374localwindows16 abr 2019
Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Troj
23RIESGO
abrir
Exploit-DB
Zyxel ZyWall 310 / ZyWall 110 / USG1900 / ATP500 / USG40 - Login Page Cross-Site Scripting
CVE-2019-9955webappshardware16 abr 2019
On Zyxel ATP200, ATP500, ATP800, USG20-VPN, USG20W-VPN, USG40, USG40W, USG60, USG60W, USG110, USG210, USG310, USG1100, U
43RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 / 1709 - CSRSS SxSSrv Cached Manifest Privilege Escalation
CVE-2019-0735localwindows16 abr 2019
An elevation of privilege vulnerability exists when the Windows Client Server Run-Time Subsystem (CSRSS) fails to proper
23RIESGO
abrir
GitHub PoC82
Apache Tomcat Remote Code Execution on Windows - CGI-BIN
CVE-2019-023216 abr 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV Delayed Virtualization MAXIMUM_ACCESS DesiredAccess Privilege Escalation
CVE-2019-0730localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV Delayed Virtualization Cross Process Handle Duplication Privilege Escalation
CVE-2019-0731localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Exploit-DB
Joomla! Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion
CVE-2019-10945webappsphp16 abr 2019
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV LuafvCopyShortName Arbitrary Short Name Privilege Escalation
CVE-2019-0796localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV PostLuafvPostReadWrite SECTION_OBJECT_POINTERS Race Condition Privilege Escalation
CVE-2019-0836localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV Delayed Virtualization Cache Manager Poisoning Privilege Escalation
CVE-2019-0805localwindows16 abr 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 1809 - LUAFV NtSetCachedSigningLevel Device Guard Bypass
CVE-2019-0732localwindows16 abr 2019
A security feature bypass vulnerability exists in Windows which could allow an attacker to bypass Device Guard when Wind
23RIESGO
abrir
Metasploit300
Oracle Application Testing Suite Post-Auth DownloadServlet Directory Traversal
CVE-2019-255716 abr 2019
Vulnerability in the Oracle Application Testing Suite component of Oracle Enterprise Manager Products Suite (subcomponen
18RIESGO
abrir
anteriorpágina 841 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.