Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
SuperMicro IPMI WebInterface 03.40 - Cross-Site Request Forgery (Add Admin)
CVE-2020-15046webappshardware15 jul 2020
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to
23RIESGO
abrir
Exploit-DB
BSA Radar 1.6.7234.24750 - Local File Inclusion
CVE-2020-14946webappsmultiple14 jul 2020
downloadFile.ashx in the Administrator section of the Surveillance module in Global RADAR BSA Radar 1.6.7234.24750 and e
23RIESGO
abrir
Exploit-DB
Trend Micro Web Security Virtual Appliance 6.5 SP2 Patch 4 Build 1901 - Remote Code Execution (Metasploit)
CVE-2020-8605webappsmultiple14 jul 2020
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitr
60RIESGO
abrir
Exploit-DB
Aruba ClearPass Policy Manager 6.7.0 - Unauthenticated Remote Command Execution
CVE-2020-7115remotelinux10 jul 2020
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon succ
35RIESGO
abrir
Exploit-DB
CompleteFTP Professional 12.1.3 - Remote Code Execution
CVE-2019-16116remotewindows09 jul 2020
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file.
23RIESGO
abrir
Exploit-DB
SuperMicro IPMI 03.40 - Cross-Site Request Forgery (Add Admin)
CVE-2020-15046webappshardware08 jul 2020
The web interface on Supermicro X10DRH-iT motherboards with BIOS 2.0a and IPMI firmware 03.40 allows remote attackers to
23RIESGO
abrir
Exploit-DB
BSA Radar 1.6.7234.24750 - Cross-Site Request Forgery (Change Password)
CVE-2020-14944webappshardware08 jul 2020
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can all
23RIESGO
abrir
Exploit-DB
Exhibitor Web UI 1.7.1 - Remote Code Execution
CVE-2019-5029CRITICALwebappsjava07 jul 2020
An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7
60RIESGO
abrir
Exploit-DB
RSA IG&L Aveksa 7.1.1 - Remote Code Execution
CVE-2019-3759MEDIUMwebappsmultiple06 jul 2020
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont
33RIESGO
abrir
Exploit-DB
Grafana 7.0.1 - Denial of Service (PoC)
CVE-2020-13379doslinux06 jul 2020
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows
60RIESGO
abrir
Exploit-DB
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI' Remote Code Execution
CVE-2020-5902CRITICALbajo ataqueransomwarewebappslinux06 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
Exploit-DB
BIG-IP 15.0.0 < 15.1.0.3 / 14.1.0 < 14.1.2.5 / 13.1.0 < 13.1.3.3 / 12.1.0 < 12.1.5.1 / 11.6.1 < 11.6.5.1 - Traffic Management User Interface 'TMUI' Remote Code Execution (PoC)
CVE-2020-5902CRITICALbajo ataqueransomwarewebappslinux05 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
Exploit-DB
OCS Inventory NG 2.7 - Remote Code Execution
CVE-2020-14947webappsmultiple02 jul 2020
OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php bec
28RIESGO
abrir
Exploit-DB
mySCADA myPRO 7 - Hardcoded Credentials
CVE-2018-11311remotehardware25 jun 2020
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack
28RIESGO
abrir
Exploit-DB
Lansweeper 7.2 - Incorrect Access Control
CVE-2020-14011localwindows23 jun 2020
Lansweeper 6.0.x through 7.2.x has a default installation in which the admin password is configured for the admin accoun
28RIESGO
abrir
Exploit-DB
WebPort 1.19.1 - Reflected Cross-Site Scripting
CVE-2019-12461webappsmultiple22 jun 2020
Web Port 1.19.1 allows XSS via the /log type parameter.
38RIESGO
abrir
Exploit-DB
FileRun 2019.05.21 - Reflected Cross-Site Scripting
CVE-2019-12905webappsmultiple22 jun 2020
FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman&section=do&page=up URI. This issue has been fixed
23RIESGO
abrir
Exploit-DB
WebPort 1.19.1 - 'setup' Reflected Cross-Site Scripting
CVE-2019-12460webappsphp22 jun 2020
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
23RIESGO
abrir
Exploit-DB
Gila CMS 1.11.8 - 'query' SQL Injection
CVE-2020-5515webappsphp16 jun 2020
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
28RIESGO
abrir
Exploit-DB
SOS JobScheduler 1.13.3 - Stored Password Decryption
CVE-2020-12712remotemultiple15 jun 2020
A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 an
23RIESGO
abrir
Exploit-DB
Sysax MultiServer 6.90 - Reflected Cross Site Scripting
CVE-2020-13228webappsmultiple12 jun 2020
An issue was discovered in Sysax Multi Server 6.90. There is reflected XSS via the /scgi sid parameter.
23RIESGO
abrir
Exploit-DB
Avaya IP Office 11 - Password Disclosure
CVE-2020-7030MEDIUMwebappsmultiple12 jun 2020
IPO Information Disclosure
33RIESGO
abrir
Exploit-DB
WinGate 9.4.1.5998 - Insecure Folder Permissions
CVE-2020-13866localwindows10 jun 2020
WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges
23RIESGO
abrir
Exploit-DB
Bludit 3.9.12 - Directory Traversal
CVE-2019-16113webappsphp09 jun 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
Exploit-DB
D-Link DIR-615 T1 20.10 - CAPTCHA Bypass
CVE-2019-17525webappshardware04 jun 2020
The login page on D-Link DIR-615 T1 20.10 devices allows remote attackers to bypass the CAPTCHA protection mechanism and
23RIESGO
abrir
Exploit-DB
Microsoft Windows - 'SMBGhost' Remote Code Execution
CVE-2020-0796CRITICALbajo ataqueransomwareremotewindows02 jun 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Exploit-DB
OpenCart 3.0.3.2 - Stored Cross Site Scripting (Authenticated)
CVE-2020-10596webappsphp02 jun 2020
OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upl
23RIESGO
abrir
Exploit-DB
vCloud Director 9.7.0.15498291 - Remote Code Execution
CVE-2020-3956remotelinux02 jun 2020
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4
28RIESGO
abrir
Exploit-DB
VMware vCenter Server 6.7 - Authentication Bypass
CVE-2020-3952CRITICALbajo ataquewebappsmultiple01 jun 2020
Under certain conditions, vmdir that ships with VMware vCenter Server, as part of an embedded or external Platform Servi
100RIESGO
abrir
Exploit-DB
WordPress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
CVE-2020-13693webappsphp01 jun 2020
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Regi
35RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.