Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'InlineArrayPush' Type Confusion
CVE-2018-8617doswindows18 ene 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Chakra - 'NewScObjectNoCtor' or 'InitProto' Type Confusion
CVE-2019-0539doswindows18 ene 2019
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
45RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Reports Developer Component 12.2.1.3 - Cross-site Scripting
CVE-2019-2413webappsmultiple17 ene 2019
Vulnerability in the Oracle Reports Developer component of Oracle Fusion Middleware (subcomponent: Valid Session). The s
23RIESGO
abrir
Exploit-DBVexDay Proof
Fortinet FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure
CVE-2018-13374MEDIUMbajo ataqueransomwarewebappshardware16 ene 2019
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 al
75RIESGO
abrir
Exploit-DBVexDay Proof
NTPsec 1.1.2 - 'config' (Authenticated) Out-of-Bounds Write Denial of Service (PoC)
CVE-2019-6442doslinux16 ene 2019
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can write one byte out of bounds in ntpd via a
28RIESGO
abrir
Exploit-DBVexDay Proof
blueman - set_dhcp_handler D-Bus Privilege Escalation (Metasploit)
CVE-2015-8612locallinux16 ene 2019
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC JIT - GetIndexedPropertyStorage Use-After-Free
CVE-2018-4442dosmultiple16 ene 2019
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - 'RestrictedErrorInfo' Unmarshal Section Handle Use-After-Free
CVE-2019-0570doswindows16 ene 2019
An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka "Windo
23RIESGO
abrir
Exploit-DBVexDay Proof
NTPsec 1.1.2 - 'ntp_control' (Authenticated) NULL Pointer Dereference (PoC)
CVE-2019-6445doslinux16 ene 2019
An issue was discovered in NTPsec before 1.1.3. An authenticated attacker can cause a NULL pointer dereference and ntpd
28RIESGO
abrir
Exploit-DBVexDay Proof
NTPsec 1.1.2 - 'ctl_getitem' Out-of-Bounds Read (PoC)
CVE-2019-6443doslinux16 ene 2019
An issue was discovered in NTPsec before 1.1.3. Because of a bug in ctl_getitem, there is a stack-based buffer over-read
50RIESGO
abrir
Exploit-DBVexDay Proof
NTPsec 1.1.2 - 'ntp_control' Out-of-Bounds Read (PoC)
CVE-2019-6444doslinux16 ene 2019
An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read be
35RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - XmlDocument Insecure Sharing Privilege Escalation
CVE-2019-0555localwindows16 ene 2019
An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - DSSVC DSOpenSharedFile Arbitrary File Open Privilege Escalation
CVE-2019-0572localwindows14 ene 2019
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - SSPI Network Authentication Session 0 Privilege Escalation
CVE-2019-0543HIGHbajo ataqueransomwarelocalwindows14 ene 2019
An elevation of privilege vulnerability exists when Windows improperly handles authentication requests, aka "Microsoft W
71RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - COM Desktop Broker Privilege Escalation
CVE-2019-0552localwindows14 ene 2019
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability."
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - DSSVC DSOpenSharedFile Arbitrary File Delete Privilege Escalation
CVE-2019-0573localwindows14 ene 2019
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - DSSVC CanonicalAndValidateFilePath Security Feature Bypass
CVE-2019-0571localwindows14 ene 2019
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - DSSVC MoveFileInheritSecurity Privilege Escalation
CVE-2019-0574localwindows14 ene 2019
An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations,
28RIESGO
abrir
Exploit-DBVexDay Proof
Dokany 1.2.0.1000 - Stack-Based Buffer Overflow Privilege Escalation
CVE-2018-5410localwindows14 ene 2019
Dokan file system driver contains a stack-based buffer overflow
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Browser Broker Cross Session Privilege Escalation
CVE-2019-0566localwindows14 ene 2019
An elevation of privilege vulnerability exists in Microsoft Edge Browser Broker COM object, aka "Microsoft Edge Elevatio
28RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - DSSVC CheckFilePermission Arbitrary File Deletion
CVE-2018-8584localwindows09 ene 2019
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (A
23RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'JSArray::shiftCountWithArrayStorage' Out-of-Bounds Read/Write
CVE-2018-4441dosmultiple02 ene 2019
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
28RIESGO
abrir
Exploit-DBVexDay Proof
WebKit JSC - 'AbstractValue::set' Use-After-Free
CVE-2018-4443dosmultiple02 ene 2019
A memory corruption issue was addressed with improved memory handling. This issue affected versions prior to iOS 12.1.1,
23RIESGO
abrir
Exploit-DBVexDay Proof
Netatalk 3.1.12 - Authentication Bypass
CVE-2018-1160CRITICALremotemultiple21 dic 2018
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RIESGO
abrir
Exploit-DBVexDay Proof
Netatalk 3.1.12 - Authentication Bypass (PoC)
CVE-2018-1160CRITICALdosmultiple21 dic 2018
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RIESGO
abrir
Exploit-DBVexDay Proof
VBScript - VbsErase Reference Leak Use-After-Free
CVE-2018-8625doswindows20 dic 2018
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
35RIESGO
abrir
Exploit-DBVexDay Proof
VBScript - MSXML Execution Policy Bypass
CVE-2018-8619doswindows20 dic 2018
A remote code execution vulnerability exists when the Internet Explorer VBScript execution policy does not properly rest
35RIESGO
abrir
Exploit-DBVexDay Proof
IBM Operational Decision Manager 8.x - XML External Entity Injection
CVE-2018-1821HIGHwebappsmultiple19 dic 2018
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) a
46RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'jscript!JsArrayFunctionHeapSort' Out-of-Bounds Write
CVE-2018-8631doswindows18 dic 2018
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
35RIESGO
abrir
Exploit-DBVexDay Proof
Safari - Proxy Object Type Confusion (Metasploit)
CVE-2018-4404HIGHremotemacos14 dic 2018
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improve
68RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.