Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
3477 exploits
Metasploit200
OpenSMTPD OOB Read Local Privilege Escalation
CVE-2020-879424 feb 2020
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RIESGO
abrir
Metasploit600
WordPress wpDiscuz Unauthenticated File Upload Vulnerability
CVE-2020-24186CRITICAL21 feb 2020
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir
Metasploit300
Apache Tomcat AJP File Read
CVE-2020-1938CRITICALbajo ataque20 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
Metasploit300
Microsoft Windows DrawIconEx OOB Write Local Privilege Elevation
CVE-2020-1054HIGHbajo ataque20 feb 2020
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
Metasploit0
Google Chrome 80 JSCreate side-effect type confusion exploit
CVE-2020-6418HIGHbajo ataque19 feb 2020
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corru
100RIESGO
abrir
Metasploit300
WordPress Duplicator File Read Vulnerability
CVE-2020-11738HIGHbajo ataque19 feb 2020
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traver
100RIESGO
abrir
Metasploit600
Aerohive NetConfig 10.0r8a LFI and log poisoning to RCE
CVE-2020-1615217 feb 2020
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0
30RIESGO
abrir
Metasploit600
SQL Server Reporting Services (SSRS) ViewState Deserialization
CVE-2020-0618CRITICALbajo ataqueransomware11 feb 2020
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
Metasploit600
Exchange Control Panel ViewState Deserialization
CVE-2020-0688HIGHbajo ataqueransomware11 feb 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Metasploit600
Service Tracing Privilege Elevation Vulnerability
CVE-2020-066811 feb 2020
An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Window
23RIESGO
abrir
Metasploit600
Unraid 6.8.0 Auth Bypass PHP Code Execution
CVE-2020-5849HIGHbajo ataque10 feb 2020
Unraid 6.8.0 allows authentication bypass.
100RIESGO
abrir
Metasploit600
Unraid 6.8.0 Auth Bypass PHP Code Execution
CVE-2020-5847CRITICALbajo ataque10 feb 2020
Unraid through 6.8.0 allows Remote Code Execution.
100RIESGO
abrir
Metasploit600
Horde CSV import arbitrary PHP code execution
CVE-2020-851807 feb 2020
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execu
60RIESGO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-8657CRITICALbajo ataque06 feb 2020
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RIESGO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-865606 feb 2020
An issue was discovered in EyesOfNetwork 5.3. The EyesOfNetwork API 2.4.2 is prone to SQL injection, allowing an unauthe
60RIESGO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-8655HIGHbajo ataque06 feb 2020
An issue was discovered in EyesOfNetwork 5.3. The sudoers configuration is prone to a privilege escalation vulnerability
98RIESGO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-946506 feb 2020
An issue was discovered in EyesOfNetwork eonweb 5.1 through 5.3 before 5.3-3. The eonweb web interface is prone to a SQL
40RIESGO
abrir
Metasploit600
EyesOfNetwork 5.1-5.3 AutoDiscovery Target Command Execution
CVE-2020-865406 feb 2020
An issue was discovered in EyesOfNetwork 5.3. An authenticated web user with sufficient privileges could abuse the AutoD
60RIESGO
abrir
Metasploit600
PlaySMS index.php Unauthenticated Template Injection Code Execution
CVE-2020-8644CRITICALbajo ataque05 feb 2020
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RIESGO
abrir
Metasploit600
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
CVE-2020-801005 feb 2020
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains an improper ACL handling vu
30RIESGO
abrir
Metasploit600
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
CVE-2020-801205 feb 2020
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi
60RIESGO
abrir
Metasploit500
Arista restricted shell escape (with privesc)
CVE-2020-901502 feb 2020
Arista DCS-7050QX-32S-R 4.20.9M, DCS-7050CX3-32S-R 4.20.11M, and DCS-7280SRAM-48C6-R 4.22.0.1F devices (and possibly oth
23RIESGO
abrir
Metasploit600
OpenSMTPD MAIL FROM Remote Code Execution
CVE-2020-7247CRITICALbajo ataque28 ene 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Metasploit600
Centreon Poller Authenticated Remote Command Execution
CVE-2019-1969927 ene 2020
There is Authenticated remote code execution in Centreon Infrastructure Monitoring Software through 19.10 via Pollers mi
23RIESGO
abrir
Metasploit300
Ricoh Driver Privilege Escalation
CVE-2019-1936322 ene 2020
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RIESGO
abrir
Metasploit300
WebLogic Server Deserialization RCE - BadAttributeValueExpException
CVE-2020-2555CRITICALbajo ataque15 ene 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
Metasploit0
WordPress InfiniteWP Client Authentication Bypass
CVE-2020-877214 ene 2020
The InfiniteWP Client plugin before 1.9.4.5 for WordPress has a missing authorization check in iwp_mmb_set_request in in
40RIESGO
abrir
Metasploit300
"Cablehaunt" Cable Modem WebSocket DoS
CVE-2019-1949407 ene 2020
Broadcom based cable modems across multiple vendors are vulnerable to a buffer overflow, which allows a remote attacker
23RIESGO
abrir
Metasploit600
D-Link Devices Unauthenticated Remote Command Execution in ssdpcgi
CVE-2019-2021524 dic 2019
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
60RIESGO
abrir
Metasploit600
D-Link DIR-859 Unauthenticated Remote Command Execution
CVE-2019-17621CRITICALbajo ataque24 dic 2019
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated rem
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.