Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
Exploit-DB
Quest NetVault Backup Server < 11.4.5 - Process Manager Service SQL Injection / Remote Code Execution
CVE-2017-17417webappsmultiple22 feb 2019
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
23RIESGO
abrir
Exploit-DB
Teracue ENC-400 - Command Injection / Missing Authentication
CVE-2018-20220webappshardware22 feb 2019
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authen
28RIESGO
abrir
Exploit-DB
WebKit JSC - reifyStaticProperty Needs to set the PropertyAttribute::CustomAccessor flag for CustomGetterSetter
CVE-2019-6215dosmultiple22 feb 2019
A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, tvOS 12.1.2, Safa
23RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware22 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC26
010 Editor template for ACE archive format & CVE-2018-2025[0-3]
CVE-2018-20250HIGHbajo ataqueransomware22 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation
CVE-2019-3475HIGHwebappslinux22 feb 2019
Local privilege escalation in Filr famtd
41RIESGO
abrir
GitHub PoC
nmweizi/CVE-2018-20250-poc-winrar
CVE-2018-20250HIGHbajo ataqueransomware22 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC30
CVE-2019-6340-Drupal SA-CORE-2019-003
CVE-2019-6340HIGHbajo ataque22 feb 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
Exploit-DB
Teracue ENC-400 - Command Injection / Missing Authentication
CVE-2018-20219webappshardware22 feb 2019
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the de
28RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation
CVE-2019-3474MEDIUMwebappslinux22 feb 2019
Path traversal vulnerability in Filr web application
33RIESGO
abrir
Exploit-DBVexDay Proof
Nuuo Central Management - (Authenticated) SQL Server SQL Injection (Metasploit)
CVE-2018-18982remotewindows22 feb 2019
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b
50RIESGO
abrir
GitHub PoC1
CVE-2019-6249 Hucart cms 复现环境
CVE-2019-624921 feb 2019
An issue was discovered in HuCart v5.7.4. There is a CSRF vulnerability that can add an admin account via /adminsys/inde
23RIESGO
abrir
Exploit-DBVexDay Proof
MikroTik RouterOS < 6.43.12 (stable) / < 6.42.12 (long-term) - Firewall and NAT Bypass
CVE-2019-3924remotehardware21 feb 2019
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The so
28RIESGO
abrir
VulnCheck XDB
local
CVE-2019-573620 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC86
CVE-2019-5736 POCs
CVE-2019-573620 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Exploit-DB
HotelDruid 2.3 - Cross-Site Scripting
CVE-2019-8937webappsphp20 feb 2019
HotelDruid 2.3.0 has XSS affecting the nsextt, cambia1, mese_fine, origine, and anno parameters in creaprezzi.php, tabel
43RIESGO
abrir
Metasploit300
Drupal RESTful Web Services unserialize() RCE
CVE-2019-6340HIGHbajo ataque20 feb 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
Exploit-DBVexDay Proof
FaceTime - Texture Processing Memory Corruption
CVE-2019-6224dosmacos20 feb 2019
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Mojave 10.
23RIESGO
abrir
Metasploit600
WordPress Crop-image Shell Upload
CVE-2019-894319 feb 2019
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Metasploit600
WordPress Crop-image Shell Upload
CVE-2019-894219 feb 2019
WordPress before 4.9.9 and 5.x before 5.0.1 allows remote code execution because an _wp_attached_file Post Meta entry ca
60RIESGO
abrir
Exploit-DB
Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting
CVE-2019-8925webappsjsp19 feb 2019
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. An Absolute Path Traversal vulnerabi
28RIESGO
abrir
Exploit-DB
XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting
CVE-2019-8923webappsphp19 feb 2019
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discont
23RIESGO
abrir
Exploit-DBVexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
CVE-2019-1003001webappsjava19 feb 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RIESGO
abrir
Exploit-DBVexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
CVE-2019-1003000webappsjava19 feb 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
Exploit-DBVexDay Proof
Jenkins Plugin Script Security < 1.50/Declarative < 1.3.4.1/Groovy < 2.61.1 - Remote Code Execution (PoC)
CVE-2019-1003002webappsjava19 feb 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RIESGO
abrir
GitHub PoC1
An app demo for test android webview security issue: CVE-2012-6636
CVE-2012-663619 feb 2019
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RIESGO
abrir
Exploit-DB
Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting
CVE-2019-8929webappsjsp19 feb 2019
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zon
28RIESGO
abrir
Exploit-DB
Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting
CVE-2019-8928webappsjsp19 feb 2019
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userMan
23RIESGO
abrir
Exploit-DB
XAMPP 5.6.8 - SQL Injection / Persistent Cross-Site Scripting
CVE-2019-8924webappsphp19 feb 2019
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
23RIESGO
abrir
Exploit-DB
Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting
CVE-2019-8926webappsjsp19 feb 2019
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in the Administration zon
23RIESGO
abrir
anteriorpágina 850 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.