Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.953exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
CVE-2021-25298HIGHbajo ataque13 feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RIESGO
abrir
Metasploit600
Nagios XI 5.5.6 to 5.7.5 - ConfigWizards Authenticated Remote Code Exection
CVE-2021-25297HIGHbajo ataque13 feb 2021
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
98RIESGO
abrir
Metasploit200
Win32k ConsoleControl Offset Confusion
CVE-2021-1732HIGHbajo ataqueransomware09 feb 2021
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit600
Advantech iView Unauthenticated Remote Code Execution
CVE-2021-2265209 feb 2021
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing authentication, which may allow a
30RIESGO
abrir
Metasploit200
Win32k ConsoleControl Offset Confusion
CVE-2022-21882HIGHbajo ataqueransomware09 feb 2021
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
Metasploit600
Micro Focus Operations Bridge Reporter Unauthenticated Command Injection
CVE-2021-22502CRITICALbajo ataque09 feb 2021
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The
100RIESGO
abrir
Metasploit600
NetMotion Mobility Server MvcUtil Java Deserialization
CVE-2021-2691408 feb 2021
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code
40RIESGO
abrir
Metasploit300
NCR Command Center Agent Remote Code Execution
CVE-2021-312207 feb 2021
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (wit
40RIESGO
abrir
Metasploit600
Wordpress Plugin Modern Events Calendar - Authenticated Remote Code Execution
CVE-2021-2414529 ene 2021
Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCE
60RIESGO
abrir
Metasploit600
Sudo Heap-Based Buffer Overflow
CVE-2021-3156HIGHbajo ataque26 ene 2021
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege
100RIESGO
abrir
Metasploit600
Apache Druid 0.20.0 Remote Command Execution
CVE-2021-2564621 ene 2021
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
60RIESGO
abrir
Metasploit600
Lucee Administrator imgProcess.cfm Arbitrary File Write
CVE-2021-21307HIGH15 ene 2021
Remote Code Exploit in Lucee Admin
78RIESGO
abrir
Metasploit600
Unauthenticated remote code execution in Ignition
CVE-2021-3129CRITICALbajo ataqueransomware13 ene 2021
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
CVE-2020-16875HIGH12 ene 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
48RIESGO
abrir
Metasploit600
Microsoft Exchange Server DlpUtils AddTenantDlpPolicy RCE
CVE-2020-17132CRITICAL12 ene 2021
Microsoft Exchange Remote Code Execution Vulnerability
65RIESGO
abrir
Metasploit300
Apache Flink JobManager Traversal
CVE-2020-17519CRITICALbajo ataque05 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
Metasploit600
Klog Server authenticate.php user Unauthenticated Command Injection
CVE-2020-3572927 dic 2020
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RIESGO
abrir
Metasploit600
Nagios XI Prior to 5.8.0 - Plugins Filename Authenticated Remote Code Exection
CVE-2020-3557819 dic 2020
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir
Metasploit600
HPE Systems Insight Manager AMF Deserialization RCE
CVE-2020-720015 dic 2020
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerabili
40RIESGO
abrir
Metasploit300
WordPress Total Upkeep Unauthenticated Backup Downloader
CVE-2020-36848HIGH12 dic 2020
Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
36RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.06 or lower - Unauthenticated Remote Code Execution
CVE-2020-2818812 dic 2020
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inje
40RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.06 or lower - Unauthenticated Remote Code Execution
CVE-2020-3566512 dic 2020
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in
60RIESGO
abrir
Metasploit600
APISIX Admin API default access token RCE
CVE-2020-1394507 dic 2020
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the
40RIESGO
abrir
Metasploit600
APISIX Admin API default access token RCE
CVE-2022-24112CRITICALbajo ataque07 dic 2020
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
Metasploit300
WordPress Easy WP SMTP Password Reset
CVE-2020-3523406 dic 2020
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in De
30RIESGO
abrir
Metasploit300
KOFFEE - Kia OFFensivE Exploit
CVE-2020-853902 dic 2020
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an atta
18RIESGO
abrir
Metasploit600
qdPM 9.1 Authenticated Arbitrary PHP File Upload (RCE)
CVE-2020-724621 nov 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir
Metasploit0
Google Chrome versions before 87.0.4280.88 integer overflow during SimplfiedLowering phase
CVE-2020-1604019 nov 2020
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir
Metasploit0
Firefox MCallGetProperty Write Side Effects Use After Free Exploit
CVE-2020-2695018 nov 2020
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable
30RIESGO
abrir
Metasploit600
OpenTSDB 2.4.0 unauthenticated command injection
CVE-2020-3547618 nov 2020
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. Th
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.