Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
79.386 exploits
Exploit-DB
BlogEngine 3.3 - XML External Entity Injection
CVE-2018-14485webappswindows09 ene 2019
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
28RIESGO
abrir
GitHub PoC678
ES File Explorer Open Port Vulnerability - CVE-2019-6447
CVE-2019-644709 ene 2019
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RIESGO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300208 ene 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RIESGO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300508 ene 2019
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.50 and earlier in src/main/java/org/jenkinsci/
23RIESGO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2018-1000861CRITICALbajo ataque08 ene 2019
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and ea
100RIESGO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300108 ene 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RIESGO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-1003029CRITICALbajo ataque08 ene 2019
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.53 and earlier in src/main/java/org/jenkinsci/
100RIESGO
abrir
Metasploit600
Jenkins ACL Bypass and Metaprogramming RCE
CVE-2019-100300008 ene 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
CVE-2018-20526webappsphp07 ene 2019
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
60RIESGO
abrir
Exploit-DB
LayerBB 1.1.1 - Persistent Cross-Site Scripting
CVE-2018-17997webappsphp07 ene 2019
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RIESGO
abrir
GitHub PoC
poc for 0263
CVE-2017-0263HIGHbajo ataque07 ene 2019
The kernel-mode drivers in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
76RIESGO
abrir
Exploit-DB
MyBB OUGC Awards Plugin 1.8.3 - Persistent Cross-Site Scripting
CVE-2019-3501webappsphp07 ene 2019
The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via a crafted award reason that is mishandled on the awards pag
23RIESGO
abrir
Exploit-DB
Roxy Fileman 1.4.5 - Unrestricted File Upload / Directory Traversal
CVE-2018-20525webappsphp07 ene 2019
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALbajo ataque07 ene 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
GitHub PoC12
漏洞利用工具
CVE-2018-2628CRITICALbajo ataque07 ene 2019
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
Exploit-DB
PLC Wireless Router GPN2.4P21-C-CN - Cross-Site Scripting
CVE-2018-20326webappscgi07 ene 2019
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage
23RIESGO
abrir
Exploit-DB
KioWare Server Version 4.9.6 - Weak Folder Permissions Privilege Escalation
CVE-2018-18435localwindows07 ene 2019
KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any
23RIESGO
abrir
Exploit-DB
Ajera Timesheets 9.10.16 - Deserialization of Untrusted Data
CVE-2018-20221webappswindows07 ene 2019
Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserializ
28RIESGO
abrir
Exploit-DB
Huawei E5330 21.210.09.00.158 - Cross-Site Request Forgery (Send SMS)
CVE-2014-5395webappshardware07 ene 2019
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13S
23RIESGO
abrir
GitHub PoC
cve-2014-0160
CVE-2014-0160HIGHbajo ataque06 ene 2019
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
CVE-2009-1324 - ASX to MP3 Converter Local Buffer Overflow. Tested on Windows XP Professional SP3
CVE-2009-132406 ene 2019
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RIESGO
abrir
GitHub PoC1
cve-2018-11776
CVE-2018-11776HIGHbajo ataque06 ene 2019
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir
GitHub PoC
CVE-2018-6389 PoC node js multisite with proxy
CVE-2018-638906 ene 2019
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the
45RIESGO
abrir
GitHub PoC
cve-2015-1427
CVE-2015-1427CRITICALbajo ataque06 ene 2019
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RIESGO
abrir
GitHub PoC
cve-2015-8103
CVE-2015-810306 ene 2019
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary co
60RIESGO
abrir
GitHub PoC
cve-2014-6271
CVE-2014-6271CRITICALbajo ataque06 ene 2019
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
GitHub PoC
cve-2015-5602
CVE-2015-560206 ene 2019
sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is d
23RIESGO
abrir
GitHub PoC
cve-2015-3306
CVE-2015-330606 ene 2019
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RIESGO
abrir
GitHub PoC
cve-2016-6515
CVE-2016-651506 ene 2019
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RIESGO
abrir
GitHub PoC
cve-2017-7494
CVE-2017-7494CRITICALbajo ataqueransomware06 ene 2019
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RIESGO
abrir
anteriorpágina 858 / 2647siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.