Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit500
Bolt CMS 3.7.0 - Authenticated Remote Code Execution
CVE-2025-34086HIGH07 may 2020
Bolt CMS Authenticated Remote Code Execution via Profile Injection and File Rename
36RIESGO
abrir
Metasploit300
Plex Unpickle Dict Windows RCE
CVE-2020-5741HIGHbajo ataque07 may 2020
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arb
100RIESGO
abrir
Metasploit300
SaltStack Salt Master Server Root Key Disclosure
CVE-2020-11652MEDIUMbajo ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Metasploit300
WebLogic Server Deserialization RCE BadAttributeValueExpException ExtComp
CVE-2020-2883CRITICALbajo ataque30 abr 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
Metasploit500
SaltStack Salt Master/Minion Unauthenticated RCE
CVE-2020-11651CRITICALbajo ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Metasploit500
SaltStack Salt Master/Minion Unauthenticated RCE
CVE-2020-11652MEDIUMbajo ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Metasploit300
SaltStack Salt Master Server Root Key Disclosure
CVE-2020-11651CRITICALbajo ataque30 abr 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Metasploit300
Wordpress LearnPress current_items Authenticated SQLi
CVE-2020-601029 abr 2020
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
50RIESGO
abrir
Metasploit600
TP-Link Cloud Cameras NCXXX Bonjour Command Injection
CVE-2020-1210929 abr 2020
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220
40RIESGO
abrir
Metasploit600
GOG GalaxyClientService Privilege Escalation
CVE-2020-7352HIGH28 abr 2020
GOG Galaxy GalaxyClientService Privilege Escalation
36RIESGO
abrir
Metasploit600
Netsweeper WebAdmin unixlogin.php Python Code Injection
CVE-2020-1316728 abr 2020
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain
40RIESGO
abrir
Metasploit600
TrixBox CE endpoint_devicemap.php Authenticated Command Execution
CVE-2020-7351HIGH28 abr 2020
Fonality Trixbox CE Post-Authentication Command Injection
48RIESGO
abrir
Metasploit400
WordPress Simple File List Unauthenticated Remote Code Execution
CVE-2020-36847CRITICAL27 abr 2020
Simple File List < 4.2.3 - Remote Code Execution
68RIESGO
abrir
Metasploit600
IBM Data Risk Manager Unauthenticated Remote Code Execution
CVE-2020-4429CRITICAL21 abr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RIESGO
abrir
Metasploit600
IBM Data Risk Manager Unauthenticated Remote Code Execution
CVE-2020-4427CRITICALbajo ataque21 abr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security rest
95RIESGO
abrir
Metasploit300
IBM Data Risk Manager Arbitrary File Download
CVE-2020-4429CRITICAL21 abr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RIESGO
abrir
Metasploit600
IBM Data Risk Manager Unauthenticated Remote Code Execution
CVE-2020-4428CRITICALbajo ataque21 abr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary co
85RIESGO
abrir
Metasploit600
IBM Data Risk Manager a3user Default Password
CVE-2020-4429CRITICAL21 abr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 contains a default password for an IDRM administrativ
65RIESGO
abrir
Metasploit300
IBM Data Risk Manager Arbitrary File Download
CVE-2020-4427CRITICALbajo ataque21 abr 2020
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote attacker to bypass security rest
95RIESGO
abrir
Metasploit0
Kibana Upgrade Assistant Telemetry Collector Prototype Pollution
CVE-2020-701217 abr 2020
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authen
23RIESGO
abrir
Metasploit300
SpamTitan Unauthenticated RCE
CVE-2020-1169817 abr 2020
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RIESGO
abrir
Metasploit600
Cisco UCS Director Cloupia Script RCE
CVE-2020-3243CRITICAL15 abr 2020
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
85RIESGO
abrir
Metasploit600
Cisco UCS Director Cloupia Script RCE
CVE-2020-3250CRITICAL15 abr 2020
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
75RIESGO
abrir
Metasploit300
Veeam ONE Agent .NET Deserialization
CVE-2020-10915CRITICAL15 abr 2020
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
85RIESGO
abrir
Metasploit300
Veeam ONE Agent .NET Deserialization
CVE-2020-10914CRITICAL15 abr 2020
This vulnerability allows remote attackers to execute arbitrary code on affected installations of VEEAM One Agent 9.5.4.
75RIESGO
abrir
Metasploit300
Zen Load Balancer Directory Traversal
CVE-2020-1149110 abr 2020
Monitoring::Logs in Zen Load Balancer 3.10.1 allows remote authenticated admins to conduct absolute path traversal attac
18RIESGO
abrir
Metasploit300
VMware vCenter Server vmdir Authentication Bypass
CVE-2020-3952CRITICALbajo ataque09 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
Metasploit300
VMware vCenter Server vmdir Information Disclosure
CVE-2020-3952CRITICALbajo ataque09 abr 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
Metasploit300
LimeSurvey Zip Path Traversals
CVE-2019-996002 abr 2020
The downloadZip function in application/controllers/admin/export.php in LimeSurvey through 3.16.1+190225 allows a relati
23RIESGO
abrir
Metasploit300
LimeSurvey Zip Path Traversals
CVE-2020-1145502 abr 2020
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileM
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.