Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
79.305 exploits
Exploit-DB
WordPress Plugin Booking Calendar 8.4.3 - (Authenticated) SQL Injection
CVE-2018-20556webappsphp14 feb 2019
SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary
28RIESGO
abrir
GitHub PoC69
exploit for CVE-2018-4193
CVE-2018-419313 feb 2019
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RIESGO
abrir
VulnCheck XDB
local
CVE-2019-573613 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Exploit-DB
Rukovoditel Project Management CRM 2.4.1 - Cross-Site Scripting
CVE-2019-7541webappsphp13 feb 2019
Rukovoditel through 2.4.1 allows XSS via a URL that lacks a module=users%2flogin substring.
23RIESGO
abrir
GitHub PoC658
PoC for CVE-2019-5736
CVE-2019-573613 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Exploit-DB
Apple macOS 10.13.5 - Local Privilege Escalation
CVE-2018-4193localmacos13 feb 2019
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RIESGO
abrir
Exploit-DB
runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (2)
CVE-2019-5736locallinux13 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Exploit-DB
runc < 1.0-rc6 (Docker < 18.09.2) - Container Breakout (1)
CVE-2019-5736locallinux12 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Exploit-DB
Skyworth GPON HomeGateways and Optical Network Terminals - Stack Overflow
CVE-2018-19524dosasp12 feb 2019
An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTB
35RIESGO
abrir
Exploit-DBVexDay Proof
Android - binder Use-After-Free of VMA via race Between reclaim and munmap
CVE-2019-1999dosandroid12 feb 2019
In binder_alloc_free_page of binder_alloc.c, there is a possible double free due to improper locking. This could lead to
23RIESGO
abrir
GitHub PoC210
Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)
CVE-2019-573612 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Exploit-DBVexDay Proof
BlogEngine.NET 3.3.6 - Directory Traversal / Remote Code Execution
CVE-2019-6714webappsaspx12 feb 2019
An issue was discovered in BlogEngine.NET through 3.3.6.0. A path traversal and Local File Inclusion vulnerability in Po
35RIESGO
abrir
VulnCheck XDB
local
CVE-2019-573612 feb 2019
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
GitHub PoC681
Linux privilege escalation exploit via snapd (CVE-2019-7304)
CVE-2019-7304HIGH12 feb 2019
Local privilege escalation via snapd socket
53RIESGO
abrir
Exploit-DBVexDay Proof
Android - binder Use-After-Free via fdget() Optimization
CVE-2019-2000dosandroid12 feb 2019
In several functions of binder.c, there is possible memory corruption due to a use after free. This could lead to local
23RIESGO
abrir
Exploit-DB
CentOS Web Panel 0.9.8.763 - Persistent Cross-Site Scripting
CVE-2019-7646webappslinux11 feb 2019
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.763 is vulnerable to Stored/Persistent XSS for the "Package
23RIESGO
abrir
Exploit-DBVexDay Proof
NUUO NVRmini - upgrade_handle.php Remote Command Execution (Metasploit)
CVE-2018-14933CRITICALbajo ataqueremotephp11 feb 2019
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RIESGO
abrir
Exploit-DBVexDay Proof
Evince - CBT File Command Injection (Metasploit)
CVE-2017-1000083locallinux11 feb 2019
backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to e
50RIESGO
abrir
Exploit-DB
Indusoft Web Studio 8.1 SP2 - Remote Code Execution
CVE-2019-6543remotemultiple11 feb 2019
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition)
28RIESGO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - DeleteRangeTimelineOperation Type Confusion (Metasploit)
CVE-2016-4117HIGHbajo ataqueremoteosx11 feb 2019
Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as
100RIESGO
abrir
Exploit-DB
Indusoft Web Studio 8.1 SP2 - Remote Code Execution
CVE-2019-6545remotemultiple11 feb 2019
AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition)
28RIESGO
abrir
GitHub PoC
Takes advantage of CVE-2018-10933
CVE-2018-10933CRITICAL10 feb 2019
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client coul
85RIESGO
abrir
GitHub PoC67
Programa ideal para robar toda la información de un dispositivo remotamente a través de la aplicación AirDroid. [CVE-2019-9599] (https://www.exploit-db.com/exploits/46337)
CVE-2019-959909 feb 2019
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash
28RIESGO
abrir
GitHub PoC5
VMware NSX SD-WAN command injection vulnerability
CVE-2018-6961HIGHbajo ataque08 feb 2019
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-6961HIGHbajo ataque08 feb 2019
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
100RIESGO
abrir
GitHub PoC
cve-2018-15877
CVE-2018-1587708 feb 2019
The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta
60RIESGO
abrir
Metasploit600
RARLAB WinRAR ACE Format Input Validation Remote Code Execution
CVE-2018-20250HIGHbajo ataqueransomware05 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
Exploit-DB
Zyxel VMG3312-B10B DSL-491HNU-B1B v2 Modem - Cross-Site Request Forgery
CVE-2019-7391webappshardware05 feb 2019
ZyXEL VMG3312-B10B DSL-491HNU-B1B v2 devices allow login/login-page.cgi CSRF.
28RIESGO
abrir
Exploit-DB
OpenMRS Platform < 2.24.0 - Insecure Object Deserialization
CVE-2018-19276CRITICALwebappsjava05 feb 2019
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated use
85RIESGO
abrir
GitHub PoC5
Exploiting CVE-2016-10277 for Secure Boot and Device Locking bypass
CVE-2016-1027704 feb 2019
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RIESGO
abrir
anteriorpágina 852 / 2644siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.