Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
OpenMediaVault rpc.php Authenticated PHP Code Injection
CVE-2020-2612428 sep 2020
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield PO
30RIESGO
abrir
Metasploit600
HorizontCMS Arbitrary PHP File Upload
CVE-2020-2738724 sep 2020
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access
23RIESGO
abrir
Metasploit600
Micro Focus Operations Bridge Reporter shrboadmin default password
CVE-2020-1185721 sep 2020
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The
23RIESGO
abrir
Metasploit600
Sophos UTM WebAdmin SID Command Injection
CVE-2020-25223CRITICALbajo ataque18 sep 2020
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RIESGO
abrir
Metasploit600
Apache Struts 2 Forced Multi OGNL Evaluation
CVE-2019-023014 sep 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir
Metasploit600
Apache Struts 2 Forced Multi OGNL Evaluation
CVE-2020-17530CRITICALbajo ataque14 sep 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
Metasploit600
MobileIron MDM Hessian-Based Java Deserialization RCE
CVE-2020-15505CRITICALbajo ataque12 sep 2020
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1,
100RIESGO
abrir
Metasploit300
WordPress File Manager Unauthenticated Remote Code Execution
CVE-2020-25213CRITICALbajo ataque09 sep 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
Metasploit600
Palo Alto Networks Authenticated Remote Code Execution
CVE-2020-2038HIGH09 sep 2020
PAN-OS: OS command injection vulnerability in the management web interface
78RIESGO
abrir
Metasploit600
MaraCMS Arbitrary PHP File Upload
CVE-2020-2504231 ago 2020
An arbitrary file upload issue exists in Mara CMS 7.5. In order to exploit this, an attacker must have a valid authentic
23RIESGO
abrir
Metasploit300
Jira Users Enumeration
CVE-2020-1418116 ago 2020
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RIESGO
abrir
Metasploit600
Artica proxy 4.30.000000 Auth Bypass service-cmds-peform Command Injection
CVE-2020-1750509 ago 2020
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter i
40RIESGO
abrir
Metasploit600
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
CVE-2020-17496CRITICALbajo ataque09 ago 2020
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbe
100RIESGO
abrir
Metasploit600
Artica proxy 4.30.000000 Auth Bypass service-cmds-peform Command Injection
CVE-2020-1750609 ago 2020
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p
60RIESGO
abrir
Metasploit600
Cisco AnyConnect Privilege Escalations (CVE-2020-3153 and CVE-2020-3433)
CVE-2020-3433HIGHbajo ataqueransomware05 ago 2020
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RIESGO
abrir
Metasploit600
Cisco AnyConnect Privilege Escalations (CVE-2020-3153 and CVE-2020-3433)
CVE-2020-3153MEDIUMbajo ataqueransomware05 ago 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RIESGO
abrir
Metasploit500
Aerospike Database UDF Lua Code Execution
CVE-2020-1315131 jul 2020
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RIESGO
abrir
Metasploit600
Mida Solutions eFramework ajaxreq.php Command Injection
CVE-2020-1592024 jul 2020
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
60RIESGO
abrir
Metasploit400
Moodle Teacher Enrollment Privilege Escalation to RCE
CVE-2020-1432120 jul 2020
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role wi
23RIESGO
abrir
Metasploit600
Apache Airflow 1.10.10 - Example DAG Remote Code Execution
CVE-2020-13927CRITICALbajo ataque14 jul 2020
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication, but th
100RIESGO
abrir
Metasploit300
SAP Unauthenticated WebService User Creation
CVE-2020-6287CRITICALbajo ataque14 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
Metasploit600
SharePoint DataSet / DataTable Deserialization
CVE-2020-1147HIGHbajo ataque14 jul 2020
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RIESGO
abrir
Metasploit600
Apache Airflow 1.10.10 - Example DAG Remote Code Execution
CVE-2020-11978HIGHbajo ataque14 jul 2020
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was disco
100RIESGO
abrir
Metasploit600
Apache OFBiz XML-RPC Java Deserialization
CVE-2023-4907013 jul 2020
Pre-auth RCE in Apache Ofbiz 18.12.09 due to XML-RPC still present
60RIESGO
abrir
Metasploit600
Apache OFBiz XML-RPC Java Deserialization
CVE-2020-949613 jul 2020
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RIESGO
abrir
Metasploit600
Apache OFBiz XML-RPC Java Deserialization
CVE-2023-5146713 jul 2020
Apache OFBiz: Pre-authentication Remote Code Execution (RCE) vulnerability
60RIESGO
abrir
Metasploit500
FreeBSD ip6_setpktopt Use-After-Free Privilege Escalation
CVE-2020-745707 jul 2020
In FreeBSD 12.1-STABLE before r359565, 12.1-RELEASE before p7, 11.4-STABLE before r362975, 11.4-RELEASE before p1, and 1
30RIESGO
abrir
Metasploit600
openSIS Unauthenticated PHP Code Execution
CVE-2020-1338130 jun 2020
openSIS through 7.4 allows SQL Injection.
30RIESGO
abrir
Metasploit600
openSIS Unauthenticated PHP Code Execution
CVE-2020-1338330 jun 2020
openSIS through 7.4 allows Directory Traversal.
30RIESGO
abrir
Metasploit600
openSIS Unauthenticated PHP Code Execution
CVE-2020-1338230 jun 2020
openSIS through 7.4 has Incorrect Access Control.
30RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.