Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit200
F5 BIG-IP TMUI Directory Traversal and File Upload RCE
CVE-2020-5902CRITICALbajo ataqueransomware30 jun 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
Metasploit600
Rockwell FactoryTalk View SE SCADA Unauthenticated Remote Code Execution
CVE-2020-12028HIGH22 jun 2020
Rockwell Automation FactoryTalk View SE
48RIESGO
abrir
Metasploit600
Rockwell FactoryTalk View SE SCADA Unauthenticated Remote Code Execution
CVE-2020-12027MEDIUM22 jun 2020
Rockwell Automation FactoryTalk View SE
40RIESGO
abrir
Metasploit600
Rockwell FactoryTalk View SE SCADA Unauthenticated Remote Code Execution
CVE-2020-12029CRITICAL22 jun 2020
Rockwell Automation FactoryTalk View SE
75RIESGO
abrir
Metasploit600
ZenTao Pro 8.8.2 Remote Code Execution
CVE-2020-7361CRITICAL20 jun 2020
ZenTao Pro Command Injection
48RIESGO
abrir
Metasploit600
Cacti color filter authenticated SQLi to RCE
CVE-2020-1429517 jun 2020
A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead
60RIESGO
abrir
Metasploit300
AnyDesk GUI Format String Write
CVE-2020-1316016 jun 2020
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RIESGO
abrir
Metasploit300
Netgear R6700v3 Unauthenticated LAN Admin Password Reset
CVE-2020-10923MEDIUM15 jun 2020
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700
50RIESGO
abrir
Metasploit300
Netgear R6700v3 Unauthenticated LAN Admin Password Reset
CVE-2020-10924HIGH15 jun 2020
This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700
58RIESGO
abrir
Metasploit600
Inductive Automation Ignition Remote Code Execution
CVE-2020-1200411 jun 2020
The affected product lacks proper authentication required to query the server on the Ignition 8 Gateway (versions prior
23RIESGO
abrir
Metasploit600
Inductive Automation Ignition Remote Code Execution
CVE-2020-1064411 jun 2020
The affected product lacks proper validation of user-supplied data, which can result in deserialization of untrusted dat
23RIESGO
abrir
Metasploit600
Trend Micro Web Security (Virtual Appliance) Remote Code Execution
CVE-2020-860510 jun 2020
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitr
60RIESGO
abrir
Metasploit600
Trend Micro Web Security (Virtual Appliance) Remote Code Execution
CVE-2020-860410 jun 2020
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensi
40RIESGO
abrir
Metasploit600
Trend Micro Web Security (Virtual Appliance) Remote Code Execution
CVE-2020-860610 jun 2020
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authent
40RIESGO
abrir
Metasploit600
Cayin xPost wayfinder_seqid SQLi to RCE
CVE-2020-7356CRITICAL04 jun 2020
Cayin xPost SQL Injection
48RIESGO
abrir
Metasploit600
Cayin CMS NTP Server RCE
CVE-2020-7357CRITICAL04 jun 2020
Cayin CMS Command Injection
55RIESGO
abrir
Metasploit600
Pandora FMS Events Remote Command Execution
CVE-2020-1385104 jun 2020
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
40RIESGO
abrir
Metasploit300
Cisco 7937G Denial-of-Service Attack
CVE-2020-1613802 jun 2020
A denial-of-service issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to remot
23RIESGO
abrir
Metasploit300
Cisco 7937G SSH Privilege Escalation
CVE-2020-1613702 jun 2020
A privilege escalation issue in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers to re
23RIESGO
abrir
Metasploit300
Cisco 7937G Denial-of-Service Reboot Attack
CVE-2020-1613902 jun 2020
A denial-of-service in Cisco Unified IP Conference Station 7937G 1-4-4-0 through 1-4-5-7 allows attackers restart the de
40RIESGO
abrir
Metasploit300
Cisco DCNM auth bypass
CVE-2019-15975CRITICAL01 jun 2020
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
85RIESGO
abrir
Metasploit300
Directory Traversal in Spring Cloud Config Server
CVE-2020-5410HIGHbajo ataque01 jun 2020
Directory Traversal with spring-cloud-config-server
100RIESGO
abrir
Metasploit300
Documalis Free PDF Editor and Scanner JPEG Stack Buffer Overflow
CVE-2020-7374MEDIUM22 may 2020
Documalis Free PDF Editor / Free PDF Scanner Stack Based Buffer Overflow
28RIESGO
abrir
Metasploit600
Geutebruck testaction.cgi Remote Command Execution
CVE-2020-1620520 may 2020
Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code
30RIESGO
abrir
Metasploit300
BIND TSIG Badtime Query Denial of Service
CVE-2020-8617HIGH19 may 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RIESGO
abrir
Metasploit600
LinuxKI Toolset 6.01 Remote Command Execution
CVE-2020-720917 may 2020
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RIESGO
abrir
Metasploit600
Plesk/myLittleAdmin ViewState .NET Deserialization
CVE-2020-1316615 may 2020
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RIESGO
abrir
Metasploit300
WordPress ChopSlider3 id SQLi Scanner
CVE-2020-1153012 may 2020
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RIESGO
abrir
Metasploit600
Wordpress Drag and Drop Multi File Uploader RCE
CVE-2020-1280011 may 2020
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Uploa
60RIESGO
abrir
Metasploit600
Pi-Hole heisenbergCompensator Blocklist OS Command Execution
CVE-2020-1110810 may 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.