Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit600
Nexus Repository Manager Java EL Injection RCE
CVE-2020-10199HIGHbajo ataque31 mar 2020
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
Metasploit300
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump
CVE-2020-572430 mar 2020
The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the HTTP server's websockify endpo
23RIESGO
abrir
Metasploit300
Grandstream UCM62xx IP PBX WebSocket Blind SQL Injection Credential Dump
CVE-2020-572330 mar 2020
The UCM6200 series 1.0.20.22 and below stores unencrypted user passwords in an SQLite database. This could allow an atta
18RIESGO
abrir
Metasploit400
Pi-Hole DHCP MAC OS Command Execution
CVE-2020-8816CRITICALbajo ataque28 mar 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
Metasploit600
GitLab File Read Remote Code Execution
CVE-2020-1097726 mar 2020
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
30RIESGO
abrir
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-10882HIGH25 mar 2020
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
68RIESGO
abrir
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-10884HIGH25 mar 2020
This vulnerability allows network-adjacent attackers execute arbitrary code on affected installations of TP-Link Archer
61RIESGO
abrir
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-2834725 mar 2020
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the sl
40RIESGO
abrir
Metasploit600
TP-Link Archer A7/C7 Unauthenticated LAN Remote Code Execution
CVE-2020-10883MEDIUM25 mar 2020
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware
48RIESGO
abrir
Metasploit600
Grandstream UCM62xx IP PBX sendPasswordEmail RCE
CVE-2020-5722CRITICALbajo ataque23 mar 2020
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafte
100RIESGO
abrir
Metasploit600
macOS cfprefsd Arbitrary File Write Local Privilege Escalation
CVE-2020-983918 mar 2020
A race condition was addressed with improved state handling. This issue is fixed in iOS 13.5 and iPadOS 13.5, macOS Cata
18RIESGO
abrir
Metasploit0
Safari in Operator Side Effect Exploit
CVE-2020-985018 mar 2020
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, wa
40RIESGO
abrir
Metasploit0
Safari in Operator Side Effect Exploit
CVE-2020-985618 mar 2020
This issue was addressed with improved checks. This issue is fixed in macOS Catalina 10.15.5. An application may be able
18RIESGO
abrir
Metasploit0
Safari in Operator Side Effect Exploit
CVE-2020-980118 mar 2020
A logic issue was addressed with improved restrictions. This issue is fixed in Safari 13.1.1. A malicious process may ca
18RIESGO
abrir
Metasploit600
VMware Fusion USB Arbitrator Setuid Privilege Escalation
CVE-2020-3950HIGHbajo ataque17 mar 2020
VMware Fusion (11.x before 11.5.2), VMware Remote Console for Mac (11.x and prior before 11.0.1) and Horizon Client for
86RIESGO
abrir
Metasploit600
Vesta Control Panel Authenticated Remote Code Execution
CVE-2020-1080817 mar 2020
Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint.
40RIESGO
abrir
Metasploit400
SMBv3 Compression Buffer Overflow
CVE-2020-0796CRITICALbajo ataqueransomware13 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Metasploit200
SMBv3 Compression Buffer Overflow
CVE-2020-0796CRITICALbajo ataqueransomware13 mar 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Metasploit300
vBulletin /ajax/api/content_infraction/getIndexableContent nodeid Parameter SQL Injection
CVE-2020-1272012 mar 2020
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
40RIESGO
abrir
Metasploit0
vBulletin /ajax/api/content_infraction/getIndexableContent nodeid Parameter SQL Injection
CVE-2020-1272012 mar 2020
vBulletin before 5.5.6pl1, 5.6.0 before 5.6.0pl1, and 5.6.1 before 5.6.1pl1 has incorrect access control.
40RIESGO
abrir
Metasploit400
Rconfig 3.x Chained Remote Code Execution
CVE-2020-1022011 mar 2020
An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php
60RIESGO
abrir
Metasploit400
Rconfig 3.x Chained Remote Code Execution
CVE-2019-1950911 mar 2020
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
60RIESGO
abrir
Metasploit300
CVE-2020-1170 Cloud Filter Arbitrary File Creation EOP
CVE-2020-17136HIGH10 mar 2020
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
41RIESGO
abrir
Metasploit600
Background Intelligent Transfer Service Arbitrary File Move Privilege Elevation Vulnerability
CVE-2020-0787HIGHbajo ataqueransomware10 mar 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir
Metasploit600
Pandora FMS Ping Authenticated Remote Code Execution
CVE-2025-34088HIGH09 mar 2020
Pandora FMS Authenticated Remote Code Execution via Ping Module
36RIESGO
abrir
Metasploit500
ManageEngine Desktop Central Java Deserialization
CVE-2020-10189CRITICALbajo ataque05 mar 2020
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RIESGO
abrir
Metasploit600
Metasploit Libnotify Plugin Arbitrary Command Execution
CVE-2020-7350MEDIUM04 mar 2020
Metasploit Framework Plugin Libnotify Command Injection
28RIESGO
abrir
Metasploit600
SharePoint Workflows XOML Injection
CVE-2020-0646CRITICALbajo ataque02 mar 2020
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RIESGO
abrir
Metasploit600
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
CVE-2019-399925 feb 2020
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RIESGO
abrir
Metasploit600
Druva inSync inSyncCPHwnet64.exe RPC Type 5 Privilege Escalation
CVE-2020-575225 feb 2020
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.