Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.955exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
PEAR Archive_Tar 1.4.10 Arbitrary File Write
CVE-2020-28949HIGHbajo ataque17 nov 2020
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper
100RIESGO
abrir
Metasploit600
Monitorr unauthenticated Remote Code Execution (RCE)
CVE-2020-2887116 nov 2020
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the s
40RIESGO
abrir
Metasploit600
WordPress AIT CSV Import Export Unauthenticated Remote Code Execution
CVE-2020-36849CRITICAL14 nov 2020
AIT CSV import/export <= 3.0.3 - Unauthenticated Arbitrary File Upload
43RIESGO
abrir
Metasploit600
Acronis TrueImage XPC Privilege Escalation
CVE-2020-2573611 nov 2020
Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC
18RIESGO
abrir
Metasploit300
Abandoned Cart for WooCommerce SQLi Scanner
CVE-2025-47608CRITICAL05 nov 2020
WordPress Recover abandoned cart for WooCommerce plugin <= 2.5 - SQL Injection Vulnerability
43RIESGO
abrir
Metasploit600
Git Remote Code Execution via git-lfs (CVE-2020-27955)
CVE-2020-2795504 nov 2020
Git LFS 2.12.0 allows Remote Code Execution.
40RIESGO
abrir
Metasploit600
SaltStack Salt REST API Arbitrary Command Execution
CVE-2020-2559203 nov 2020
In SaltStack Salt through 3002, salt-netapi improperly validates eauth credentials and tokens. A user can bypass authent
30RIESGO
abrir
Metasploit600
SaltStack Salt REST API Arbitrary Command Execution
CVE-2020-16846CRITICALbajo ataque03 nov 2020
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
100RIESGO
abrir
Metasploit600
Rapid7 Metasploit Framework msfvenom APK Template Command Injection
CVE-2020-7384HIGH29 oct 2020
Client-Side Command Injection in Rapid7 Metasploit
68RIESGO
abrir
Metasploit600
Micro Focus UCMDB Java Deserialization Unauthenticated Remote Code Execution
CVE-2020-11854CRITICAL28 oct 2020
Arbitrary code execution vlnerability in Operation bridge Manager, Application Performance Management and Operations Bridge (containerized) products.
85RIESGO
abrir
Metasploit600
Micro Focus UCMDB Java Deserialization Unauthenticated Remote Code Execution
CVE-2020-11853HIGH28 oct 2020
Arbitrary code execution vulnerability on multiple Micro Focus products
58RIESGO
abrir
Metasploit600
Micro Focus Operations Bridge Manager Authenticated Remote Code Execution
CVE-2020-11853HIGH28 oct 2020
Arbitrary code execution vulnerability on multiple Micro Focus products
58RIESGO
abrir
Metasploit600
Micro Focus Operations Bridge Manager / Reporter Local Privilege Escalation
CVE-2020-11858HIGH28 oct 2020
Code execution with escalated privilegesn vlnerability in Operation bridge Manager and Operations Bridge (containerized) products.
36RIESGO
abrir
Metasploit600
Micro Focus Operations Bridge Manager / Reporter Local Privilege Escalation
CVE-2020-1185528 oct 2020
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The
18RIESGO
abrir
Metasploit600
Pulse Secure VPN gzip RCE
CVE-2020-8260HIGHbajo ataque26 oct 2020
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform
100RIESGO
abrir
Metasploit300
WordPress Loginizer log SQLi Scanner
CVE-2020-2761521 oct 2020
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa
30RIESGO
abrir
Metasploit300
Oracle Solaris SunSSH PAM parse_user_name() Buffer Overflow
CVE-2020-14871CRITICALbajo ataque20 oct 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RIESGO
abrir
Metasploit600
NSClient++ 0.5.2.35 - ExternalScripts Authenticated Remote Code Execution
CVE-2025-34079HIGH20 oct 2020
NSClient++ Authenticated Remote Code Execution via ExternalScripts API
36RIESGO
abrir
Metasploit600
NSClient++ 0.5.2.35 - Privilege escalation
CVE-2025-34078HIGH20 oct 2020
NSClient++ 0.5.2.35 Local Privilege Escalation via ExternalScripts and Web Interface
36RIESGO
abrir
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14750CRITICALbajo ataque20 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14883HIGHbajo ataque20 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
Metasploit600
Nagios XI 5.5.0-5.7.3 - Snmptrap Authenticated Remote Code Exection
CVE-2020-579220 oct 2020
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user
30RIESGO
abrir
Metasploit600
Nagios XI 5.6.0-5.7.3 - Mibs.php Authenticated Remote Code Exection
CVE-2020-579120 oct 2020
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RIESGO
abrir
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14882CRITICALbajo ataque20 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
Metasploit600
Microsoft SharePoint Server-Side Include and ViewState RCE
CVE-2020-16952HIGH13 oct 2020
Microsoft SharePoint Remote Code Execution Vulnerability
58RIESGO
abrir
Metasploit600
Gogs Git Hooks Remote Code Execution
CVE-2020-1586707 oct 2020
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privile
40RIESGO
abrir
Metasploit600
Gitea Git Hooks Remote Code Execution
CVE-2020-1414407 oct 2020
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer envir
40RIESGO
abrir
Metasploit300
SAP Solution Manager remote unauthorized OS commands execution
CVE-2020-6207CRITICALbajo ataque03 oct 2020
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RIESGO
abrir
Metasploit300
SAP Solution Manager remote unauthorized OS commands execution
CVE-2020-6207CRITICALbajo ataque03 oct 2020
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RIESGO
abrir
Metasploit600
FlexDotnetCMS Arbitrary ASP File Upload
CVE-2020-2738628 sep 2020
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and e
40RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.