Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
13.947 exploits
GitHub PoC
kkhacklabs/CVE-2020-14750
CVE-2020-14750CRITICALbajo ataque09 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC56
MuirlandOracle/CVE-2019-15107
CVE-2019-15107CRITICALbajo ataqueransomware09 nov 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC7
QmF0c3UK/CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque09 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC13
[CVE-2020-14882] Oracle WebLogic Server Authenticated Remote Code Execution (RCE)
CVE-2020-14883HIGHbajo ataque09 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC3
[CVE-2020-14882] Oracle WebLogic Server Authentication Bypass
CVE-2020-14882CRITICALbajo ataque09 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC
AaronCaiii/CVE-2019-0708-POC
CVE-2019-0708CRITICALbajo ataqueransomware06 nov 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
GitHub PoC3
CVE-2020-28351 - Reflected Cross-Site Scripting attack in ShoreTel version 19.46.1802.0.
CVE-2020-2835106 nov 2020
The conferencing component on Mitel ShoreTel 19.46.1802.0 devices could allow an unauthenticated attacker to conduct a r
43RIESGO
abrir
GitHub PoC2
Writeup on CVE-2020-28328: SuiteCRM Log File Remote Code Execution plus some bonus Cross-Site Scripting
CVE-2020-2832806 nov 2020
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain
50RIESGO
abrir
GitHub PoC48
PoC para las vulnerabilidades CVE-2020-14750 y cve-2020-14882
CVE-2020-14750CRITICALbajo ataque06 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC
CVE-2020-0796-POC
CVE-2020-0796CRITICALbajo ataqueransomware06 nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC1
mingchen-script/CVE-2020-1472-visualizer
CVE-2020-1472MEDIUMbajo ataqueransomware05 nov 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC3
mmioimm/cve-2020-14882
CVE-2020-14882CRITICALbajo ataque05 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC3
CVE-2020-15999
CVE-2020-15999CRITICALbajo ataque04 nov 2020
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploi
90RIESGO
abrir
GitHub PoC19
CVE-2020-14882/14883/14750
CVE-2020-14882CRITICALbajo ataque04 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC11
Re-implementation of VirtueSecurity's benigncertain-monitor
CVE-2016-6415HIGHbajo ataque04 nov 2020
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RIESGO
abrir
GitHub PoC13
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process.
CVE-2017-976903 nov 2020
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RIESGO
abrir
GitHub PoC1
CVE-2020-14882 detection script
CVE-2020-14882CRITICALbajo ataque03 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC145
CVE-2020-14882_ALL综合利用工具,支持命令回显检测、批量命令回显、外置xml无回显命令执行等功能。
CVE-2020-14882CRITICALbajo ataque03 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC8
(CVE-2020-14882) Oracle Weblogic Unauthorized bypass RCE test script
CVE-2020-14882CRITICALbajo ataque01 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC12
CVE-2020-14882批量验证工具。
CVE-2020-14882CRITICALbajo ataque31 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC13
Exploiting CVE-2014-3153, AKA Towelroot.
CVE-2014-3153HIGHbajo ataque31 oct 2020
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RIESGO
abrir
GitHub PoC1
CuteNews Avatar 2.1.2 Remote Code Execution Vulnerability
CVE-2019-1144730 oct 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir
GitHub PoC
alexfrancow/CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque30 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC2
Bash script to exploit the Oracle's Weblogic Unauthenticated Remote Command Execution - CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque29 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC7
CVE-2020-14882 EXP 回显
CVE-2020-14882CRITICALbajo ataque29 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC17
CVE-2020-14882 Weblogic-Exp
CVE-2020-14882CRITICALbajo ataque29 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
GitHub PoC2
Scans for Microsoft Exchange Versions with masscan
CVE-2020-0688HIGHbajo ataqueransomware29 oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC
Un semplice exploit che sfrutta CVE-2015-7297, CVE-2015-7857 and CVE-2015-7858 per elencare gli utenti con la psw del db
CVE-2015-729729 oct 2020
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
GitHub PoC
Windows 7 LPE
CVE-2020-1054HIGHbajo ataque28 oct 2020
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle o
98RIESGO
abrir
GitHub PoC29
CVE-2020–14882 by Jang
CVE-2020-14882CRITICALbajo ataque28 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
anteriorpágina 386 / 465siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.