Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
GitHub PoC1
An app demo for test android webview security issue: CVE-2012-6636
CVE-2012-663619 feb 2019
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RIESGO
abrir
Exploit-DB
Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2 - Path Traversal / Cross-Site Scripting
CVE-2019-8928webappsjsp19 feb 2019
An issue was discovered in Zoho ManageEngine Netflow Analyzer Professional 7.0.0.2. XSS exists in /netflow/jspui/userMan
23RIESGO
abrir
GitHub PoC
Easy RM to MP3 Converter es un software que sufre de una vulnerabiliad de desbordamiento de buffer basada en la pila o StackBufferOverflow lo cual puede permite a los atacantes remotos ejecutar código arbitrario a través de un nombre de archivo largo en un archivo de lista de reproducción (.pls)
CVE-2009-133018 feb 2019
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long fil
28RIESGO
abrir
Exploit-DB
Zoho ManageEngine ServiceDesk Plus (SDP) < 10.0 build 10012 - Arbitrary File Upload
CVE-2019-8394HIGHbajo ataquewebappsjsp18 feb 2019
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to upload arbitrary files via l
98RIESGO
abrir
Exploit-DB
MISP 2.4.97 - SQL Command Execution via Command Injection in STIX Module
CVE-2018-19908webappsphp18 feb 2019
An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped file
28RIESGO
abrir
Exploit-DB
qdPM 9.1 - 'search[keywords]' Cross-Site Scripting
CVE-2019-8390webappsphp18 feb 2019
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
38RIESGO
abrir
Exploit-DB
qdPM 9.1 - 'type' Cross-Site Scripting
CVE-2019-8391webappsphp18 feb 2019
qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
23RIESGO
abrir
Exploit-DB
WordPress Plugin WooCommerce - GloBee (cryptocurrency) Payment Gateway 1.1.1 - Payment Bypass / Unauthorized Order Status Spoofing
CVE-2018-20782webappsphp18 feb 2019
The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.
28RIESGO
abrir
Exploit-DB
mIRC < 7.55 - 'Custom URI Protocol Handlers' Remote Command Execution
CVE-2019-6453remotewindows18 feb 2019
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The a
35RIESGO
abrir
Metasploit300
Total.js prior to 3.2.4 Directory Traversal
CVE-2019-890318 feb 2019
index.js in Total.js Platform before 3.2.3 allows path traversal.
40RIESGO
abrir
Exploit-DB
Master IP CAM 01 3.3.4.2103 - Remote Command Execution
CVE-2019-8387webappscgi18 feb 2019
MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.
35RIESGO
abrir
Exploit-DB
Webiness Inventory 2.3 - 'ProductModel' Arbitrary File Upload
CVE-2019-8404webappsphp18 feb 2019
An issue was discovered in Webiness Inventory 2.3. The ProductModel component allows Arbitrary File Upload via a crafted
23RIESGO
abrir
GitHub PoC48
Proof of calc for CVE-2019-6453
CVE-2019-645318 feb 2019
mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The a
35RIESGO
abrir
Exploit-DB
Jinja2 2.10 - 'from_string' Server Side Template Injection
CVE-2019-8341webappspython15 feb 2019
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where
35RIESGO
abrir
Exploit-DBVexDay Proof
Linux - 'kvm_ioctl_create_device()' NULL Pointer Dereference
CVE-2019-6974doslinux15 feb 2019
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because
28RIESGO
abrir
GitHub PoC7
getshell test
CVE-2019-573615 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-100300015 feb 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
GitHub PoC316
Jenkins RCE Proof-of-Concept: SECURITY-1266 / CVE-2019-1003000 (Script Security), CVE-2019-1003001 (Pipeline: Groovy), CVE-2019-1003002 (Pipeline: Declarative)
CVE-2019-100300015 feb 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
Exploit-DB
MyBB Trash Bin Plugin 1.1.3 - Cross-Site Scripting / Cross-Site Request Forgery
CVE-2018-14575webappsphp15 feb 2019
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CS
23RIESGO
abrir
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'ssl-provider-name' Cross-Site Scripting
CVE-2018-20009webappsphp14 feb 2019
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.
38RIESGO
abrir
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'assets/add/dns.php' Cross-Site Scripting
CVE-2018-19914webappsphp14 feb 2019
DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.
38RIESGO
abrir
GitHub PoC1
likekabin/CVE-2019-5736
CVE-2019-573614 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC
likekabin/cve-2019-5736-poc
CVE-2019-573614 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC14
runc容器逃逸漏洞预警
CVE-2019-573614 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Exploit-DB
WordPress Plugin Booking Calendar 8.4.3 - (Authenticated) SQL Injection
CVE-2018-20556webappsphp14 feb 2019
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary
28RIESGO
abrir
Exploit-DB
LayerBB 1.1.2 - Cross-Site Request Forgery (Add Admin)
CVE-2018-17996webappsphp14 feb 2019
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_
23RIESGO
abrir
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'ssl-accounts.php username' Cross-Site Scripting
CVE-2018-20010webappsphp14 feb 2019
DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.
38RIESGO
abrir
Exploit-DBVexDay Proof
DomainMOD 4.11.01 - 'category.php CatagoryName_ StakeHolder' Cross-Site Scripting
CVE-2018-20011webappsphp14 feb 2019
DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.
38RIESGO
abrir
GitHub PoC6
Payload Generator
CVE-2019-7304HIGH14 feb 2019
Local privilege escalation via snapd socket
53RIESGO
abrir
VulnCheck XDB
local
CVE-2019-573614 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
anteriorpágina 851 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.