Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
CVE-2020-0618CRITICALbajo ataqueransomwareremotewindows17 sep 2020
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
Exploit-DB
Piwigo 2.10.1 - Cross Site Scripting
CVE-2020-9467webappsphp16 sep 2020
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
28RIESGO
abrir
Exploit-DB
ThinkAdmin 6 - Arbitrarily File Read
CVE-2020-25540webappsphp15 sep 2020
ThinkAdmin v6 is affected by a directory traversal vulnerability. An unauthorized attacker can read arbitrarily file on
60RIESGO
abrir
Exploit-DBVexDay Proof
CuteNews 2.1.2 - Remote Code Execution
CVE-2019-11447webappsphp10 sep 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir
Exploit-DB
ZTE Router F602W - Captcha Bypass
CVE-2020-6862webappshardware10 sep 2020
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could lo
23RIESGO
abrir
Exploit-DB
ManageEngine Applications Manager 14700 - Remote Code Execution (Authenticated)
CVE-2020-14008webappsjava07 sep 2020
Zoho ManageEngine Applications Manager 14710 and before allows an authenticated admin user to upload a vulnerable jar in
35RIESGO
abrir
Exploit-DB
Rukovoditel 2.7.1 - Remote Code Execution (2) (Authenticated)
CVE-2020-11819webappsphp02 sep 2020
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RIESGO
abrir
Exploit-DB
Mida eFramework 2.9.0 - Remote Code Execution
CVE-2020-15920webappsmultiple27 ago 2020
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
60RIESGO
abrir
Exploit-DB
Microsoft SharePoint Server 2019 - Remote Code Execution
CVE-2020-1147HIGHbajo ataquewebappsaspx17 ago 2020
A remote code execution vulnerability exists in .NET Framework, Microsoft SharePoint, and Visual Studio when the softwar
100RIESGO
abrir
Exploit-DBVexDay Proof
Bludit 3.9.2 - Authentication Bruteforce Mitigation Bypass
CVE-2019-17240LOWwebappsphp17 ago 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
Exploit-DB
Artica Proxy 4.3.0 - Authentication Bypass
CVE-2020-17506webappshardware13 ago 2020
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p
60RIESGO
abrir
Exploit-DB
ACTi NVR3 Standard or Professional Server 3.0.12.42 - Denial of Service (PoC)
CVE-2020-15956doswindows05 ago 2020
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer
28RIESGO
abrir
Exploit-DB
Pi-hole 4.3.2 - Remote Code Execution (Authenticated)
CVE-2020-8816CRITICALbajo ataquewebappspython04 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
Exploit-DB
Cisco Adaptive Security Appliance Software 9.7 - Unauthenticated Arbitrary File Deletion
CVE-2020-3187CRITICALwebappshardware29 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RIESGO
abrir
Exploit-DB
Wordpress Plugin Maintenance Mode by SeedProd 5.1.1 - Persistent Cross-Site Scripting
CVE-2020-15038webappsphp29 jul 2020
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
23RIESGO
abrir
Exploit-DB
Cisco Adaptive Security Appliance Software 9.11 - Local File Inclusion
CVE-2020-3452HIGHbajo ataquewebappshardware28 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
Exploit-DB
F5 Big-IP 13.1.3 Build 0.0.6 - Local File Inclusion
CVE-2020-5902CRITICALbajo ataqueransomwarewebappshardware26 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
Exploit-DB
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - 'hash' SQL Injection (Unauthenticated)
CVE-2019-20361HIGHwebappsphp26 jul 2020
There was a flaw in the WordPress plugin, Email Subscribers & Newsletters before 4.3.1, that allowed SQL statements to b
78RIESGO
abrir
Exploit-DB
Rails 5.0.1 - Remote Code Execution
CVE-2020-8163webappsruby26 jul 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RIESGO
abrir
Exploit-DB
WordPress Plugin Email Subscribers & Newsletters 4.2.2 - Unauthenticated File Download
CVE-2019-19985MEDIUMwebappsphp26 jul 2020
The WordPress plugin, Email Subscribers & Newsletters, before 4.2.3 had a flaw that allowed unauthenticated file downloa
70RIESGO
abrir
Exploit-DB
Bludit 3.9.2 - Directory Traversal
CVE-2019-16113webappsmultiple26 jul 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
Exploit-DB
pfSense 2.4.4-p3 - Cross-Site Request Forgery
CVE-2019-16667webappsphp26 jul 2020
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executi
35RIESGO
abrir
Exploit-DB
Bio Star 2.8.2 - Local File Inclusion
CVE-2020-15050webappsmultiple26 jul 2020
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary fi
50RIESGO
abrir
Exploit-DB
ManageEngine Applications Manager 13 - 'MenuHandlerServlet' SQL Injection
CVE-2016-9488webappsjava26 jul 2020
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
23RIESGO
abrir
Exploit-DB
INNEO Startup TOOLS 2018 M040 13.0.70.3804 - Remote Code Execution
CVE-2020-15492webappsmultiple26 jul 2020
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RIESGO
abrir
Exploit-DB
Docsify.js 4.11.4 - Reflective Cross-Site Scripting
CVE-2020-7680webappsmultiple22 jul 2020
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a
23RIESGO
abrir
Exploit-DB
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
CVE-2020-15364webappsphp22 jul 2020
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
23RIESGO
abrir
Exploit-DB
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
CVE-2020-15363webappsphp22 jul 2020
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
23RIESGO
abrir
Exploit-DB
CMSUno 1.6 - Cross-Site Request Forgery (Change Admin Password)
CVE-2020-15600webappsphp17 jul 2020
An issue was discovered in CMSUno before 1.6.1. uno.php allows CSRF to change the admin password.
23RIESGO
abrir
Exploit-DB
Zyxel Armor X1 WAP6806 - Directory Traversal
CVE-2020-14461webappshardware15 jul 2020
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.