Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
79.386 exploits
VulnCheck XDB
infoleak
CVE-2019-1652HIGHbajo ataque24 ene 2019
Cisco Small Business RV320 and RV325 Routers Command Injection Vulnerability
100RIESGO
abrir
Exploit-DBVexDay Proof
Ghostscript 9.26 - Pseudo-Operator Remote Code Execution
CVE-2019-6116remotelinux24 ene 2019
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-8581HIGHbajo ataqueransomware24 ene 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of
76RIESGO
abrir
Exploit-DB
SirsiDynix e-Library 3.5.x - Cross-Site Scripting
CVE-2018-20503webappscgi24 ene 2019
Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.
23RIESGO
abrir
Exploit-DB
Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation
CVE-2018-15708webappslinux23 ene 2019
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RIESGO
abrir
GitHub PoC1
This is a exp of CVE-2018-15473
CVE-2018-15473MEDIUM23 ene 2019
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Exploit-DB
Nagios XI 5.5.6 - Remote Code Execution / Privilege Escalation
CVE-2018-15710webappslinux23 ene 2019
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RIESGO
abrir
GitHub PoC1
Writeup for CVE-2017-16995 Linux BPF Local Privilege Escalation
CVE-2017-1699522 ene 2019
The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial
50RIESGO
abrir
Exploit-DB
Linux Kernel 4.13 - 'compat_get_timex()' Leak Kernel Pointer
CVE-2018-11508doslinux21 ene 2019
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitiv
23RIESGO
abrir
Metasploit300
Microsoft Exchange Privilege Escalation Exploit
CVE-2019-072421 ene 2019
An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka 'Microsoft Exchange Server Elevation of
23RIESGO
abrir
Exploit-DB
GattLib 0.2 - Stack Buffer Overflow
CVE-2019-6498remotelinux21 ene 2019
GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
23RIESGO
abrir
GitHub PoC1
cve-2018-15961
CVE-2018-15961CRITICALbajo ataque21 ene 2019
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unr
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-10562CRITICALbajo ataqueransomware20 ene 2019
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_ac
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-4878HIGHbajo ataqueransomware20 ene 2019
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RIESGO
abrir
GitHub PoC
CVE-2015-2794 auto finder
CVE-2015-279420 ene 2019
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-8174HIGHbajo ataqueransomware20 ene 2019
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7494CRITICALbajo ataqueransomware20 ene 2019
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
GitHub PoC6
praveensutar/CVE-2019-6263-Joomla-POC
CVE-2019-626318 ene 2019
An issue was discovered in Joomla! before 3.9.2. Inadequate checks of the Global Configuration Text Filter settings allo
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InitClass' Type Confusion
CVE-2019-0539doswindows18 ene 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8453HIGHbajo ataqueransomware18 ene 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
VulnCheck XDB
local
CVE-2018-8453HIGHbajo ataqueransomware18 ene 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
CVE-2019-0567doswindows18 ene 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InlineArrayPush' Type Confusion
CVE-2018-8617doswindows18 ene 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'JsBuiltInEngineInterfaceExtensionObject::InjectJsBuiltInLibraryCode' Use-After-Free
CVE-2019-0568doswindows18 ene 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Exploit-DB
SCP Client - Multiple Vulnerabilities (SSHtranger Things)
CVE-2019-6110MEDIUMremotemultiple18 ene 2019
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-T
38RIESGO
abrir
Exploit-DB
SCP Client - Multiple Vulnerabilities (SSHtranger Things)
CVE-2019-6111MEDIUMremotemultiple18 ene 2019
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses wh
45RIESGO
abrir
Exploit-DB
Pydio / AjaXplorer < 5.0.4 - (Unauthenticated) Arbitrary File Upload
CVE-2013-6227webappsphp18 ene 2019
Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
CVE-2019-0539doswindows18 ene 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
GitHub PoC2
cve-2018-8453 exp
CVE-2018-8453HIGHbajo ataqueransomware18 ene 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
GitHub PoC119
cve-2018-8453 exp
CVE-2018-8453HIGHbajo ataqueransomware18 ene 2019
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir
anteriorpágina 855 / 2647siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.