Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
Nagios XI 5.7.3 - 'mibs.php' Remote Command Injection (Authenticated)
CVE-2020-5791webappsphp28 oct 2020
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RIESGO
abrir
Exploit-DB
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
CVE-2020-14864HIGHbajo ataquewebappslinux28 oct 2020
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ins
100RIESGO
abrir
Exploit-DB
Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
CVE-2019-15813webappsphp27 oct 2020
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RIESGO
abrir
Exploit-DB
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
CVE-2017-16783webappsphp26 oct 2020
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
23RIESGO
abrir
Exploit-DBVexDay Proof
Bludit 3.9.2 - Auth Bruteforce Bypass
CVE-2019-17240LOWwebappsphp23 oct 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
Exploit-DB
HiSilicon video encoders - RCE via unauthenticated upload of malicious firmware
CVE-2020-24217webappshardware19 oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo
35RIESGO
abrir
Exploit-DB
Jenkins 2.63 - Sandbox bypass in pipeline: Groovy plug-in
CVE-2019-1003030CRITICALbajo ataquewebappsjava19 oct 2020
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir
Exploit-DB
HiSilicon Video Encoders - Unauthenticated file disclosure via path traversal
CVE-2020-24219webappshardware19 oct 2020
An issue was discovered on URayTech IPTV/H.264/H.265 video encoders through 1.97. Attackers can send crafted unauthentic
28RIESGO
abrir
Exploit-DB
HiSilicon Video Encoders - Full admin access via backdoor password
CVE-2020-24215webappshardware19 oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can use har
28RIESGO
abrir
Exploit-DB
HiSilicon Video Encoders - RCE via unauthenticated command injection
CVE-2020-24217webappshardware19 oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. The file-upload endpo
35RIESGO
abrir
Exploit-DB
HiSilicon Video Encoders - Unauthenticated RTSP buffer overflow (DoS)
CVE-2020-24214webappshardware19 oct 2020
An issue was discovered in the box application on HiSilicon based IPTV/H.264/H.265 video encoders. Attackers can send a
35RIESGO
abrir
Exploit-DB
Typesetter CMS 5.1 - Arbitrary Code Execution (Authenticated)
CVE-2020-25790webappsphp19 oct 2020
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RIESGO
abrir
Exploit-DB
Hostel Management System 2.1 - Cross Site Scripting (Multiple Fields)
CVE-2020-25270webappsphp19 oct 2020
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RIESGO
abrir
Exploit-DB
Seat Reservation System 1.0 - Unauthenticated SQL Injection
CVE-2020-25762webappsphp16 oct 2020
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RIESGO
abrir
Exploit-DB
Cisco ASA and FTD 9.6.4.42 - Path Traversal
CVE-2020-3452HIGHbajo ataquewebappshardware12 oct 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
Exploit-DB
Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
CVE-2019-19493webappsphp09 oct 2020
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, lea
23RIESGO
abrir
Exploit-DB
D-Link DSR-250N 3.12 - Denial of Service (PoC)
CVE-2020-26567webappshardware08 oct 2020
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed
28RIESGO
abrir
Exploit-DB
SpamTitan 7.07 - Unauthenticated Remote Code Execution
CVE-2020-11698webappsphp05 oct 2020
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RIESGO
abrir
Exploit-DB
Mida eFramework 2.8.9 - Remote Code Execution
CVE-2020-15922webappshardware28 sep 2020
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)
35RIESGO
abrir
Exploit-DB
MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
CVE-2020-17382localwindows28 sep 2020
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RIESGO
abrir
Exploit-DB
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
CVE-2020-15930webappsmultiple28 sep 2020
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
23RIESGO
abrir
Exploit-DB
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
CVE-2018-17431webappsmultiple22 sep 2020
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir
Exploit-DB
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
CVE-2020-25453webappsphp21 sep 2020
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote
23RIESGO
abrir
Exploit-DB
Mida eFramework 2.9.0 - Back Door Access
CVE-2020-15921webappshardware21 sep 2020
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric
28RIESGO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11699webappsmultiple18 sep 2020
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php woul
23RIESGO
abrir
Exploit-DB
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
CVE-2019-15715webappsphp18 sep 2020
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
35RIESGO
abrir
Exploit-DB
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
CVE-2017-7615webappsphp18 sep 2020
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RIESGO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11804webappsmultiple18 sep 2020
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page ma
23RIESGO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11700webappsmultiple18 sep 2020
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.
23RIESGO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11803webappsmultiple18 sep 2020
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with th
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.