Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Citrix SD-WAN Appliance 10.2.2 - Authentication Bypass / Remote Command Execution
CVE-2019-12991HIGHbajo ataquewebappscgi12 jul 2019
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of
93RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Negative nAxes
CVE-2019-1127doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Negative cubeStackDepth
CVE-2019-1118doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling Due to Incorrect Handling of blendArray
CVE-2019-1119doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readStrings
CVE-2019-1122doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling While Processing CFF Blend DICT Operator
CVE-2019-1123doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Stack Corruption in OpenType Font Handling due to Out-of-Bounds cubeStackDepth
CVE-2019-1117doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readCharset
CVE-2019-1128doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Buffer Overflow in OpenType Font Handling in readFDSelect
CVE-2019-1120doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Unbounded iFD
CVE-2019-1121doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft DirectWrite / AFDKO - Heap-Based Out-of-Bounds Read/Write in OpenType Font Handling Due to Empty ROS Strings
CVE-2019-1124doswindows10 jul 2019
A remote code execution vulnerability exists in the way that DirectWrite handles objects in memory, aka 'DirectWrite Rem
28RIESGO
abrir
Exploit-DBVexDay Proof
Serv-U FTP Server - prepareinstallation Privilege Escalation (Metasploit)
CVE-2019-12181locallinux03 jul 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat - CGIServlet enableCmdLineArguments Remote Code Execution (Metasploit)
CVE-2019-0232remotewindows03 jul 2019
When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0
60RIESGO
abrir
Exploit-DBVexDay Proof
Mac OS X TimeMachine - 'tmdiagnose' Command Injection Privilege Escalation (Metasploit)
CVE-2019-8513localmacos02 jul 2019
This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to
38RIESGO
abrir
Exploit-DBVexDay Proof
LibreNMS 1.46 - 'addhost' Remote Code Execution
CVE-2018-20434webappsphp28 jun 2019
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
50RIESGO
abrir
Exploit-DBVexDay Proof
Mozilla Spidermonkey - IonMonkey 'Array.prototype.pop' Type Confusion
CVE-2019-11707HIGHbajo ataquedosmultiple26 jun 2019
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow
83RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.5.6 - Magpie_debug.php Root Remote Code Execution (Metasploit)
CVE-2018-15710remotelinux26 jun 2019
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RIESGO
abrir
Exploit-DBVexDay Proof
Nagios XI 5.5.6 - Magpie_debug.php Root Remote Code Execution (Metasploit)
CVE-2018-15708remotelinux26 jun 2019
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'CmpAddRemoveContainerToCLFSLog' Arbitrary File/Directory Creation
CVE-2019-0959HIGHdoswindows24 jun 2019
Windows Common Log File System Driver Elevation of Privilege Vulnerability
41RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Font Cache Service - Insecure Sections Privilege Escalation
CVE-2019-0943doswindows24 jun 2019
Windows ALPC Elevation of Privilege Vulnerability
23RIESGO
abrir
Exploit-DBVexDay Proof
Cisco Prime Infrastructure Health Monitor - TarArchive Directory Traversal (Metasploit)
CVE-2019-1821HIGHremotelinux20 jun 2019
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RIESGO
abrir
Exploit-DBVexDay Proof
Serv-U FTP Server < 15.1.7 - Local Privilege Escalation (1)
CVE-2019-12181locallinux18 jun 2019
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RIESGO
abrir
Exploit-DBVexDay Proof
Exim 4.87 - 4.91 - Local Privilege Escalation
CVE-2019-10149CRITICALbajo ataquelocallinux17 jun 2019
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message(
100RIESGO
abrir
Exploit-DBVexDay Proof
LibreNMS - addhost Command Injection (Metasploit)
CVE-2018-20434remotelinux05 jun 2019
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to htm
50RIESGO
abrir
Exploit-DBVexDay Proof
IBM Websphere Application Server - Network Deployment Untrusted Data Deserialization Remote Code Execution (Metasploit)
CVE-2019-4279CRITICALremotewindows05 jun 2019
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with
85RIESGO
abrir
Exploit-DBVexDay Proof
IBM Websphere Application Server - Network Deployment Untrusted Data Deserialization Remote Code Execution (Metasploit)
CVE-2019-8352remotewindows05 jun 2019
By default, BMC PATROL Agent through 11.3.01 uses a static encryption key for encrypting/decrypting user credentials sen
23RIESGO
abrir
Exploit-DBVexDay Proof
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
CVE-2018-5406webappsphp03 jun 2019
The Quest Kace K1000 Appliance misconfigures the Cross-Origin Resource Sharing (CORS) mechanism.
28RIESGO
abrir
Exploit-DBVexDay Proof
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
CVE-2018-5405webappsphp03 jun 2019
The Quest Kace K1000 Appliance is vulnerable to JavaScript injection.
23RIESGO
abrir
Exploit-DBVexDay Proof
KACE System Management Appliance (SMA) < 9.0.270 - Multiple Vulnerabilities
CVE-2018-5404webappsphp03 jun 2019
The Quest Kace K1000 Appliance is vulnerable to multiple Blind SQL Injections.
23RIESGO
abrir
Exploit-DBVexDay Proof
Qualcomm Android - Kernel Use-After-Free via Incorrect set_page_dirty() in KGSL
CVE-2019-10529dosandroid29 may 2019
Possible use after free issue due to race condition while attempting to mark the entry pages as dirty using function set
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.