Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
79.386 exploits
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Arbitrary mach Port Name Deallocation in XPC Services due to Invalid mach Message Parsing in _xpc_serializer_unpack
CVE-2019-6218dosmultiple31 ene 2019
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave
23RIESGO
abrir
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 XNU - 'vm_map_copy' Optimization which Requires Atomicity isn't Atomic
CVE-2019-6205dosmultiple31 ene 2019
A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 12.1.3, macOS Moja
23RIESGO
abrir
Exploit-DBVexDay Proof
macOS XNU - Copy-on-Write Behaviour Bypass via Partial-Page Truncation of File
CVE-2019-6208dosmacos31 ene 2019
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 12.1.3, macOS Moja
23RIESGO
abrir
Exploit-DBVexDay Proof
macOS < 10.14.3 / iOS < 12.1.3 - Kernel Heap Overflow in PF_KEY due to Lack of Bounds Checking when Retrieving Statistics
CVE-2019-6213dosmultiple31 ene 2019
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.3,
23RIESGO
abrir
GitHub PoC1
NSE script to scan for Cisco routers vulnerable to CVE-2019-1653
CVE-2019-1653HIGHbajo ataque30 ene 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-1653HIGHbajo ataque30 ene 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
Exploit-DBVexDay Proof
iOS/macOS 10.13.6 - 'if_ports_used_update_wakeuuid()' 16-byte Uninitialized Kernel Stack Disclosure
CVE-2019-6209dosmultiple30 ene 2019
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input
23RIESGO
abrir
GitHub PoC1
Python 3 implementation of an existing CVE-2011-3556 proof of concept (PoC).
CVE-2011-355629 ene 2019
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RIESGO
abrir
GitHub PoC
Exploit script for Crossfire 1.9.0
CVE-2006-123629 ene 2019
Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrar
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-999528 ene 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Firepower Management Center 6.2.2.2 / 6.2.3 - Cross-Site Scripting
CVE-2019-1642MEDIUMwebappshardware28 ene 2019
Cisco Firepower Management Center Cross-Site Scripting Vulnerability
33RIESGO
abrir
Exploit-DB
Rundeck Community Edition < 3.0.13 - Persistent Cross-Site Scripting
CVE-2019-6804webappsjava28 ene 2019
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascrip
23RIESGO
abrir
Exploit-DB
AirTies Air5341 Modem 1.0.0.12 - Cross-Site Request Forgery
CVE-2019-6967webappshardware28 ene 2019
AirTies Air5341 1.0.0.12 devices allow cgi-bin/login CSRF.
28RIESGO
abrir
Exploit-DB
MyBB IP History Logs Plugin 1.0.2 - Cross-Site Scripting
CVE-2019-6979webappsphp28 ene 2019
An issue was discovered in the User IP History Logs (aka IP_History_Logs) plugin 1.0.2 for MyBB. There is XSS via the ad
23RIESGO
abrir
Exploit-DB
CloudMe Sync 1.11.2 Buffer Overflow - WoW64 (DEP Bypass)
CVE-2018-6892remotewindows_x86-6428 ene 2019
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
Exploit-DB
LogonBox Limited / Hypersocket Nervepoint Access Manager - (Unauthenticated) Insecure Direct Object Reference
CVE-2019-6716webappsmultiple28 ene 2019
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 thr
23RIESGO
abrir
Exploit-DB
Sricam gSOAP 2.8 - Denial of Service
CVE-2019-6973doshardware28 ene 2019
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server
28RIESGO
abrir
Exploit-DB
Cisco RV300 / RV320 - Information Disclosure
CVE-2019-1653HIGHbajo ataquewebappshardware28 ene 2019
Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability
100RIESGO
abrir
GitHub PoC2
DVR username password recovery.
CVE-2018-999528 ene 2019
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-1885226 ene 2019
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-in
35RIESGO
abrir
Exploit-DBVexDay Proof
iOS/macOS - 'task_swap_mach_voucher()' Use-After-Free
CVE-2019-6225dosmultiple25 ene 2019
A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 12.1.3, macOS Mojave 10.14.
28RIESGO
abrir
Exploit-DBVexDay Proof
Cisco RV320 Dual Gigabit WAN VPN Router 1.4.2.15 - Command Injection
CVE-2019-1652HIGHbajo ataquewebappshardware25 ene 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir
Metasploit600
Schneider Electric Pelco Endura NET55XX Encoder
CVE-2019-681425 ene 2019
A CWE-287: Improper Authentication vulnerability exists in the NET55XX Encoder with firmware prior to version 2.1.9.7 wh
50RIESGO
abrir
Exploit-DB
Lua 5.3.5 - 'debug.upvaluejoin' Use After Free
CVE-2019-6706dosmultiple25 ene 2019
Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attack
28RIESGO
abrir
Exploit-DB
WordPress Plugin Wisechat 2.6.3 - Reverse Tabnabbing
CVE-2019-6780webappsphp25 ene 2019
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPost
23RIESGO
abrir
Exploit-DB
Zyxel NBG-418N v2 Modem 1.00(AAXM.6)C0 - Cross-Site Request Forgery
CVE-2019-6710webappshardware24 ene 2019
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-1652HIGHbajo ataque24 ene 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir
Exploit-DB
SirsiDynix e-Library 3.5.x - Cross-Site Scripting
CVE-2018-20503webappscgi24 ene 2019
Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Ghostscript 9.26 - Pseudo-Operator Remote Code Execution
CVE-2019-6116remotelinux24 ene 2019
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-8581HIGHbajo ataqueransomware24 ene 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RIESGO
abrir
anteriorpágina 854 / 2647siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.