Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
vsftpd 2.3.4 - Backdoor Command Execution
CVE-2011-2523remoteunix12 abr 2021
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RIESGO
abrir
Exploit-DBVexDay Proof
Codiad 2.8.4 - Remote Code Execution (Authenticated)
CVE-2018-14009webappsmultiple23 mar 2021
Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.
35RIESGO
abrir
Exploit-DBVexDay Proof
SonLogger 4.2.3.3 - Unauthenticated Arbitrary File Upload (Metasploit)
CVE-2021-27964webappsmultiple15 mar 2021
SonLogger before 6.4.1 is affected by Unauthenticated Arbitrary File Upload. An attacker can send a POST request to /Con
50RIESGO
abrir
Exploit-DBVexDay Proof
Golden FTP Server 4.70 - 'PASS' Buffer Overflow (2)
CVE-2006-6576remotewindows09 mar 2021
Heap-based buffer overflow in Golden FTP Server (goldenftpd) 1.92 allows remote attackers to cause a denial of service (
50RIESGO
abrir
Exploit-DBVexDay Proof
AnyDesk 5.5.2 - Remote Code Execution
CVE-2020-13160remotelinux03 mar 2021
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execut
60RIESGO
abrir
Exploit-DBVexDay Proof
Zen Cart 1.5.7b - Remote Code Execution (Authenticated)
CVE-2021-3291webappsphp02 mar 2021
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RIESGO
abrir
Exploit-DBVexDay Proof
FortiLogger 4.4.2.2 - Unauthenticated Arbitrary File Upload (Metasploit)
CVE-2021-3378webappsmultiple01 mar 2021
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUpl
60RIESGO
abrir
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Unauthenticated Command Injection (Metasploit)
CVE-2020-35729webappsphp25 ene 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RIESGO
abrir
Exploit-DBVexDay Proof
Wordpress Plugin Simple Job Board 2.9.3 - Authenticated File Read (Metasploit)
CVE-2020-35749webappsphp21 ene 2021
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RIESGO
abrir
Exploit-DBVexDay Proof
Apache Flink 1.11.0 - Unauthenticated Arbitrary File Read (Metasploit)
CVE-2020-17519CRITICALbajo ataquewebappsjava08 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
Exploit-DBVexDay Proof
Gitea 1.7.5 - Remote Code Execution
CVE-2019-11229webappsmultiple06 ene 2021
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to rem
35RIESGO
abrir
Exploit-DBVexDay Proof
Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
CVE-2020-10199HIGHbajo ataquewebappsjava06 ene 2021
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
Exploit-DBVexDay Proof
PaperStream IP (TWAIN) 1.42.0.5685 - Local Privilege Escalation
CVE-2018-16156localwindows06 ene 2021
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes u
23RIESGO
abrir
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Command Injection (Unauthenticated)
CVE-2020-35729webappsphp05 ene 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RIESGO
abrir
Exploit-DBVexDay Proof
Razer Chroma SDK Server 3.16.02 - Race Condition Remote File Execution
CVE-2020-16602remotewindows26 nov 2020
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a ra
23RIESGO
abrir
Exploit-DBVexDay Proof
ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit)
CVE-2019-12725webappslinux24 nov 2020
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
CVE-2020-1938CRITICALbajo ataquewebappsmultiple13 nov 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
Exploit-DBVexDay Proof
Bludit 3.9.2 - Auth Bruteforce Bypass
CVE-2019-17240LOWwebappsphp23 oct 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
Exploit-DBVexDay Proof
CuteNews 2.1.2 - Remote Code Execution
CVE-2019-11447webappsphp10 sep 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir
Exploit-DBVexDay Proof
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
CVE-2019-17240LOWwebappsphp17 ago 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
Exploit-DBVexDay Proof
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
CVE-2020-11108webappslinux26 may 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
Exploit-DBVexDay Proof
Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
CVE-2020-13166remotewindows25 may 2020
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RIESGO
abrir
Exploit-DBVexDay Proof
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
CVE-2017-15889remotehardware25 may 2020
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
50RIESGO
abrir
Exploit-DBVexDay Proof
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation
CVE-2020-5752localwindows22 may 2020
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir
Exploit-DBVexDay Proof
WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
CVE-2020-2555CRITICALbajo ataqueremotemultiple22 may 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
Exploit-DBVexDay Proof
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
CVE-2020-11108remotephp19 may 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
Exploit-DBVexDay Proof
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
CVE-2016-4437CRITICALbajo ataqueremotemultiple01 may 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
Exploit-DBVexDay Proof
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
CVE-2019-3999localwindows29 abr 2020
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RIESGO
abrir
Exploit-DBVexDay Proof
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
CVE-2019-15752HIGHbajo ataquelocalwindows28 abr 2020
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RIESGO
abrir
Exploit-DBVexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
CVE-2020-5847CRITICALbajo ataqueremotelinux20 abr 2020
Unraid through 6.8.0 allows Remote Code Execution.
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.