Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
Exploit-DB
Joomla! Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion
CVE-2019-10945webappsphp16 abr 2019
An issue was discovered in Joomla! before 3.9.5. The Media Manager component does not properly sanitize the folder param
35RIESGO
abrir
Exploit-DBVexDay Proof
CuteNews 2.1.2 - 'avatar' Remote Code Execution (Metasploit)
CVE-2019-11447remotephp15 abr 2019
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir
GitHub PoC190
Apache Tomcat Remote Code Execution on Windows
CVE-2019-023215 abr 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
Metasploit300
Remote Mouse RCE
CVE-2022-3365CRITICAL15 abr 2019
Emote Interactive Remote Mouse Server command injection due to weak encoding
63RIESGO
abrir
Metasploit600
Kentico CMS Staging SyncServer Unserialize Remote Command Execution
CVE-2019-10068CRITICALbajo ataque15 abr 2019
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-023215 abr 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
Exploit-DBVexDay Proof
Cisco RV130W Routers - Management Interface Remote Command Execution (Metasploit)
CVE-2019-1663CRITICALremotehardware15 abr 2019
Cisco RV110W, RV130W, and RV215W Routers Management Interface Remote Command Execution Vulnerability
85RIESGO
abrir
GitHub PoC3
CVE-2018-16858 exploit implementation
CVE-2018-16858HIGH14 abr 2019
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir
Metasploit600
Mac OS X Feedback Assistant Race Condition
CVE-2019-856513 abr 2019
A race condition was addressed with additional validation. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4. A mali
43RIESGO
abrir
Metasploit600
Mac OS X TimeMachine (tmdiagnose) Command Injection Privilege Escalation
CVE-2019-851313 abr 2019
This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to
38RIESGO
abrir
GitHub PoC1
🔍 Explore and test the CVE-2025-49844 (RediShell) vulnerability in Redis with this practical lab environment for secure education and research.
CVE-2025-49844CRITICAL13 abr 2019
Redis Lua Use-After-Free may lead to remote code execution
85RIESGO
abrir
GitHub PoC1
Exploit for the CVE-2019-5736 runc vulnerability
CVE-2019-573613 abr 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC57
jenkins CVE-2017-1000353 POC
CVE-2017-1000353CRITICALbajo ataque12 abr 2019
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RIESGO
abrir
Exploit-DB
CyberArk EPM 10.2.1.603 - Security Restrictions Bypass
CVE-2018-14894localwindows12 abr 2019
CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file
23RIESGO
abrir
Exploit-DBVexDay Proof
Zimbra Collaboration - Autodiscover Servlet XXE and ProxyServlet SSRF (Metasploit)
CVE-2019-9670CRITICALbajo ataqueremotelinux12 abr 2019
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XX
100RIESGO
abrir
Exploit-DB
ATutor < 2.2.4 - 'file_manager' Remote Code Execution (Metasploit)
CVE-2019-11446webappsphp12 abr 2019
An issue was discovered in ATutor through 2.2.4. It allows the user to run commands on the server with the teacher user
23RIESGO
abrir
Exploit-DBVexDay Proof
Zimbra Collaboration - Autodiscover Servlet XXE and ProxyServlet SSRF (Metasploit)
CVE-2019-9621HIGHbajo ataqueremotelinux12 abr 2019
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RIESGO
abrir
VulnCheck XDB
info-leak
CVE-2017-1000353CRITICALbajo ataque12 abr 2019
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code exe
100RIESGO
abrir
GitHub PoC50
rogue-kdc/CVE-2019-1253
CVE-2019-1253HIGHbajo ataqueransomware10 abr 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir
GitHub PoC
Confluence Widget Connector RCE - ptquan
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC2
likekabin/CVE-2019-0841
CVE-2019-0841HIGHbajo ataqueransomware10 abr 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
GitHub PoC39
Confluence Widget Connector RCE
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC145
Confluence 未授权 RCE (CVE-2019-3396) 漏洞
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC174
CVE-2019-3396 confluence SSTI RCE
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-1253HIGHbajo ataqueransomware10 abr 2019
An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.To e
76RIESGO
abrir
Metasploit600
Apache Tomcat CGIServlet enableCmdLineArguments Vulnerability
CVE-2019-023210 abr 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
GitHub PoC
s1xg0d/CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALbajo ataqueransomware10 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALbajo ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
anteriorpágina 842 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.