Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
Exploit-DB
Microsoft Windows - AppX Deployment Service Privilege Escalation
CVE-2019-0841HIGHbajo ataqueransomwarelocalwindows09 abr 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
Exploit-DB
TP-LINK TL-WR940N / TL-WR941ND - Buffer Overflow
CVE-2019-6989remotehardware09 abr 2019
TP-Link TL-WR940N is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the ipAddrDispos
28RIESGO
abrir
GitHub PoC
xiaoshuier/CVE-2019-3396
CVE-2019-3396CRITICALbajo ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-3396CRITICALbajo ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC22
Confluence Widget Connector path traversal (CVE-2019-3396)
CVE-2019-3396CRITICALbajo ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
Confluence Widget Connector RCE
CVE-2019-3396CRITICALbajo ataqueransomware09 abr 2019
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
Exploit-DB
Apache Axis 1.4 - Remote Code Execution
CVE-2019-0227remotemultiple09 abr 2019
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2
45RIESGO
abrir
Exploit-DB
ManageEngine ServiceDesk Plus 9.3 - User Enumeration
CVE-2019-10273webappsjava08 abr 2019
Information leakage vulnerability in the /mc login page in ManageEngine ServiceDesk Plus 9.3 software allows authenticat
23RIESGO
abrir
Exploit-DB
ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities
CVE-2019-9591webappsphp08 abr 2019
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE before 19.49.1500.0 allows remote attack
23RIESGO
abrir
Exploit-DB
ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities
CVE-2019-9592webappsphp08 abr 2019
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to
23RIESGO
abrir
Exploit-DB
Apache 2.4.17 < 2.4.38 - 'apache2ctl graceful' 'logrotate' Local Privilege Escalation
CVE-2019-0211HIGHbajo ataquelocallinux08 abr 2019
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privilege
83RIESGO
abrir
Exploit-DB
Bolt CMS 3.6.6 - Cross-Site Request Forgery / Remote Code Execution
CVE-2019-10874webappsphp08 abr 2019
Cross Site Request Forgery (CSRF) in the bolt/upload File Upload feature in Bolt CMS 3.6.6 allows remote attackers to ex
23RIESGO
abrir
Exploit-DBVexDay Proof
QNAP Netatalk < 3.1.12 - Authentication Bypass
CVE-2018-1160CRITICALremotemultiple08 abr 2019
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RIESGO
abrir
Exploit-DB
SaLICru -SLC-20-cube3(5) - HTML Injection
CVE-2019-10887webappshardware08 abr 2019
A reflected HTML injection vulnerability on Salicru SLC-20-cube3(5) devices running firmware version cs121-SNMP v4.54.82
23RIESGO
abrir
Exploit-DB
ShoreTel Connect ONSITE < 19.49.1500.0 - Multiple Vulnerabilities
CVE-2019-9593webappsphp08 abr 2019
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 18.82.2000.0 allows remote attackers to
23RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 5.0.0 - Crop-image Shell Upload (Metasploit)
CVE-2019-8943remotephp05 abr 2019
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Exploit-DBVexDay Proof
WordPress Core 5.0.0 - Crop-image Shell Upload (Metasploit)
CVE-2019-8942remotephp05 abr 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RIESGO
abrir
GitHub PoC239
PoC code for CVE-2019-0841 Privilege Escalation vulnerability
CVE-2019-0841HIGHbajo ataqueransomware05 abr 2019
An elevation of privilege vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard li
98RIESGO
abrir
GitHub PoC1
likekabin/CVE-2019-0604_sharepoint_CVE
CVE-2019-0604CRITICALbajo ataqueransomware04 abr 2019
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup
100RIESGO
abrir
Exploit-DB
AIDA64 Engineer 5.99.4900 - 'Load from file' Field Buffer Overflow (SEH)
CVE-2019-10843localwindows04 abr 2019
20RIESGO
abrir
GitHub PoC4
ManageEngine Service Desk Plus 10.0 Privilaged account Hijacking
CVE-2019-1000804 abr 2019
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session
28RIESGO
abrir
Exploit-DBVexDay Proof
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1652HIGHbajo ataqueremotehardware03 abr 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JavaScriptCore - Out-Of-Bounds Access in FTL JIT due to LICM Moving Array Access Before the Bounds Check
CVE-2019-8518dosmultiple03 abr 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12
28RIESGO
abrir
Exploit-DBVexDay Proof
SpiderMonkey - IonMonkey Compiled Code Fails to Update Inferred Property Types (Type Confusion)
CVE-2019-9813dosmultiple03 abr 2019
Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbi
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco RV320 and RV325 - Unauthenticated Remote Code Execution (Metasploit)
CVE-2019-1653HIGHbajo ataqueremotehardware03 abr 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JavaScriptCore - CodeBlock Dangling Watchpoints Use-After-Free
CVE-2019-8558dosmultiple03 abr 2019
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JavaScriptCore - 'createRegExpMatchesArray' Type Confusion
CVE-2019-8506HIGHbajo ataquedosmultiple03 abr 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.2, tvOS 12.2, watchOS
76RIESGO
abrir
Exploit-DBVexDay Proof
iOS < 12.2 / macOS < 10.14.4 XNU - pidversion Increment During execve is Unsafe
CVE-2019-8514dosmultiple03 abr 2019
A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS
23RIESGO
abrir
GitHub PoC
Example and demo setup for Heartbleed vulnerability (CVE-2014-0160). This should be used for testing purposes only!💔
CVE-2014-0160HIGHbajo ataque03 abr 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
Exploit-DB
WordPress Plugin PayPal Checkout Payment Gateway 1.6.8 - Parameter Tampering
CVE-2019-7441webappsphp02 abr 2019
cgi-bin/webscr?cmd=_cart in the WooCommerce PayPal Checkout Payment Gateway plugin 1.6.8 for WordPress allows Parameter
23RIESGO
abrir
anteriorpágina 843 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.