Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
19.066 exploits
Exploit-DBVexDay Proof
Oracle Weblogic Server Deserialization RCE - Raw Object (Metasploit)
CVE-2015-4852CRITICALbajo ataqueremotemultiple28 mar 2019
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
Exploit-DBVexDay Proof
Spidermonkey - IonMonkey Type Inference is Incorrect for Constructors Entered via OSR
CVE-2019-9791dosmultiple26 mar 2019
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects w
28RIESGO
abrir
Exploit-DBVexDay Proof
VMware Workstation 14.1.5 / VMware Player 15.0.2 - Host VMX Process Impersonation Hijack Privilege Escalation
CVE-2018-5511localwindows25 mar 2019
On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Manageme
28RIESGO
abrir
Exploit-DBVexDay Proof
VMware Workstation 14.1.5 / VMware Player 15 - Host VMX Process COM Class Hijack Privilege Escalation
CVE-2019-5512localwindows25 mar 2019
VMware Workstation (15.x before 15.0.3, 14.x before 14.1.6) running on Windows does not handle COM classes appropriately
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft VBScript - VbsErase Memory Corruption
CVE-2019-0667doswindows19 mar 2019
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka 'Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome < M73 - Double-Destruction Race in StoragePartitionService
CVE-2019-5797HIGHdosmultiple19 mar 2019
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
41RIESGO
abrir
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003002remotejava19 mar 2019
A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src
60RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome < M73 - MidiManagerWin Use-After-Free
CVE-2019-5789dosmultiple19 mar 2019
An integer overflow that leads to a use-after-free in WebMIDI in Google Chrome on Windows prior to 73.0.3683.75 allowed
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - VBScript Execution Policy Bypass in MSHTML
CVE-2019-0768doswindows19 mar 2019
A security feature bypass vulnerability exists when Internet Explorer VBScript execution policy does not properly restri
35RIESGO
abrir
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003000remotejava19 mar 2019
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
Exploit-DBVexDay Proof
Jenkins 2.137 and Pipeline Groovy Plugin 2.61 - ACL Bypass and Metaprogramming Remote Code Execution (Metasploit)
CVE-2019-1003001remotejava19 mar 2019
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins
60RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Flash click2play Bypass with CObjectElement::FinalCreateObject
CVE-2019-0612doswindows19 mar 2019
A security feature bypass vulnerability exists when Click2Play protection in Microsoft Edge improperly handles flash obj
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome < M73 - Data Race in ExtensionsGuestViewMessageFilter
CVE-2019-5796dosmultiple19 mar 2019
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially explo
23RIESGO
abrir
Exploit-DBVexDay Proof
Google Chrome < M73 - FileSystemOperationRunner Use-After-Free
CVE-2019-5788dosmultiple19 mar 2019
An integer overflow that leads to a use-after-free in Blink Storage in Google Chrome on Linux prior to 73.0.3683.75 allo
23RIESGO
abrir
Exploit-DBVexDay Proof
BMC Patrol Agent - Privilege Escalation Code Execution Execution (Metasploit)
CVE-2018-20735remotemultiple18 mar 2019
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for l
38RIESGO
abrir
Exploit-DBVexDay Proof
CMS Made Simple Showtime2 Module 3.6.2 - (Authenticated) Arbitrary File Upload
CVE-2019-9692webappsphp15 mar 2019
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tika-server < 1.18 - Command Injection
CVE-2018-1335remotewindows13 mar 2019
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Exploit-DBVexDay Proof
elFinder PHP Connector < 2.1.48 - 'exiftran' Command Injection (Metasploit)
CVE-2019-9194remotephp13 mar 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
Exploit-DBVexDay Proof
FreeBSD - Intel SYSRET Privilege Escalation (Metasploit)
CVE-2012-0217localfreebsd_x86-6407 mar 2019
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RIESGO
abrir
Exploit-DBVexDay Proof
Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit)
CVE-2019-6340HIGHbajo ataqueremotephp07 mar 2019
Drupal core - Highly critical - Remote Code Execution
100RIESGO
abrir
Exploit-DBVexDay Proof
Android - getpidcon() Usage in Hardware binder ServiceManager Permits ACL Bypass
CVE-2019-2023dosandroid06 mar 2019
In ServiceManager::add function in the hardware service manager, there is an insecure permissions check based on the PID
23RIESGO
abrir
Exploit-DBVexDay Proof
Android - binder Use-After-Free via racy Initialization of ->allow_user_free
CVE-2019-2025dosandroid06 mar 2019
In binder_thread_read of binder.c, there is a possible use-after-free due to improper locking. This could lead to local
23RIESGO
abrir
Exploit-DBVexDay Proof
Linux < 4.20.14 - Virtual Address 0 is Mappable via Privileged write() to /proc/*/mem
CVE-2019-9213doslinux06 mar 2019
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RIESGO
abrir
Exploit-DBVexDay Proof
elFinder 2.1.47 - 'PHP connector' Command Injection
CVE-2019-9194webappsphp04 mar 2019
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
Exploit-DBVexDay Proof
Linux < 4.14.103 / < 4.19.25 - Out-of-Bounds Read and Write in SNMP NAT Module
CVE-2019-9162doslinux01 mar 2019
In the Linux kernel before 4.20.12, net/ipv4/netfilter/nf_nat_snmp_basic_main.c in the SNMP NAT module has insufficient
23RIESGO
abrir
Exploit-DBVexDay Proof
Joomla! Component J2Store < 3.3.7 - SQL Injection
CVE-2019-9184webappsphp28 feb 2019
SQL injection vulnerability in the J2Store plugin 3.x before 3.3.7 for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation
CVE-2019-3474MEDIUMwebappslinux22 feb 2019
Path traversal vulnerability in Filr web application
33RIESGO
abrir
Exploit-DBVexDay Proof
Nuuo Central Management - (Authenticated) SQL Server SQL Injection (Metasploit)
CVE-2018-18982remotewindows22 feb 2019
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can b
50RIESGO
abrir
Exploit-DBVexDay Proof
WinRAR 5.61 - Path Traversal
CVE-2018-20250HIGHbajo ataqueransomwarelocalwindows22 feb 2019
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
Exploit-DBVexDay Proof
Micro Focus Filr 3.4.0.217 - Path Traversal / Local Privilege Escalation
CVE-2019-3475HIGHwebappslinux22 feb 2019
Local privilege escalation in Filr famtd
41RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.