Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
WordPress Plugin BBPress 2.5 - Unauthenticated Privilege Escalation
CVE-2020-13693webappsphp01 jun 2020
An unauthenticated privilege-escalation issue exists in the bbPress plugin before 2.6.5 for WordPress when New User Regi
35RIESGO
abrir
Exploit-DBVexDay Proof
Pi-hole 4.4.0 - Remote Code Execution (Authenticated)
CVE-2020-11108webappslinux26 may 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
Exploit-DBVexDay Proof
Synology DiskStation Manager - smart.cgi Remote Command Execution (Metasploit)
CVE-2017-15889remotehardware25 may 2020
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RIESGO
abrir
Exploit-DBVexDay Proof
Plesk/myLittleAdmin - ViewState .NET Deserialization (Metasploit)
CVE-2020-13166remotewindows25 may 2020
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcod
60RIESGO
abrir
Exploit-DBVexDay Proof
WebLogic Server - Deserialization RCE - BadAttributeValueExpException (Metasploit)
CVE-2020-2555CRITICALbajo ataqueremotemultiple22 may 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
Exploit-DBVexDay Proof
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation
CVE-2020-5752localwindows22 may 2020
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir
Exploit-DB
OpenEDX platform Ironwood 2.5 - Remote Code Execution
CVE-2020-13144webappsmultiple21 may 2020
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>Ne
28RIESGO
abrir
Exploit-DB
BIND - 'TSIG' Denial of Service
CVE-2020-8617HIGHdosmultiple20 may 2020
A logic error in code which checks TSIG validity can be used to trigger an assertion failure in tsig.c
78RIESGO
abrir
Exploit-DB
Submitty 20.04.01 - Persistent Cross-Site Scripting
CVE-2020-12882webappsphp19 may 2020
Submitty through 20.04.01 allows XSS via upload of an SVG document, as demonstrated by an attack by a Student against a
23RIESGO
abrir
Exploit-DBVexDay Proof
Pi-Hole - heisenbergCompensator Blocklist OS Command Execution (Metasploit)
CVE-2020-11108remotephp19 may 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
Exploit-DB
Mikrotik Router Monitoring System 1.2.3 - 'community' SQL Injection
CVE-2020-13118webappshardware18 may 2020
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community
23RIESGO
abrir
Exploit-DB
Oracle Hospitality RES 3700 5.7 - Remote Code Execution
CVE-2019-3025webappsjava18 may 2020
Vulnerability in the Oracle Hospitality RES 3700 component of Oracle Food and Beverage Applications. The supported versi
28RIESGO
abrir
Exploit-DB
HP LinuxKI 6.01 - Remote Command Injection
CVE-2020-7209remotemultiple18 may 2020
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
60RIESGO
abrir
Exploit-DB
WordPress Plugin ChopSlider 3.4 - 'id' SQL Injection
CVE-2020-11530webappsphp12 may 2020
A blind SQL injection vulnerability is present in Chop Slider 3, a WordPress plugin. The vulnerability is introduced in
60RIESGO
abrir
Exploit-DB
Cisco Digital Network Architecture Center 1.3.1.4 - Persistent Cross-Site Scripting
CVE-2019-15253MEDIUMwebappsjava12 may 2020
Cisco Digital Network Architecture Center Stored Cross-Site Scripting Vulnerability
33RIESGO
abrir
Exploit-DB
SolarWinds MSP PME Cache Service 1.1.14 - Insecure File Permissions
CVE-2020-12608localwindows11 may 2020
An issue was discovered in SolarWinds MSP PME (Patch Management Engine) Cache Service before 1.1.15 in the Advanced Moni
28RIESGO
abrir
Exploit-DB
Pi-hole < 4.4 - Authenticated Remote Code Execution / Privileges Escalation
CVE-2020-11108webappslinux10 may 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
Exploit-DB
Pi-hole < 4.4 - Authenticated Remote Code Execution
CVE-2020-11108webappslinux10 may 2020
The Gravity updater in Pi-hole through 4.4 allows an authenticated adversary to upload arbitrary files. This can be abus
60RIESGO
abrir
Exploit-DB
Saltstack 3000.1 - Remote Code Execution
CVE-2020-11651CRITICALbajo ataqueremotemultiple05 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Exploit-DB
Saltstack 3000.1 - Remote Code Execution
CVE-2020-11652MEDIUMbajo ataqueremotemultiple05 may 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
Exploit-DB
Apache OFBiz 17.12.03 - Cross-Site Request Forgery (Account Takeover)
CVE-2019-0235webappsjava01 may 2020
Apache OFBiz 17.12.01 is vulnerable to some CSRF attacks.
35RIESGO
abrir
Exploit-DBVexDay Proof
Apache Shiro 1.2.4 - Cookie RememberME Deserial RCE (Metasploit)
CVE-2016-4437CRITICALbajo ataqueremotemultiple01 may 2020
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
Exploit-DBVexDay Proof
Druva inSync Windows Client 6.5.2 - Local Privilege Escalation
CVE-2019-3999localwindows29 abr 2020
Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, u
38RIESGO
abrir
Exploit-DBVexDay Proof
Docker-Credential-Wincred.exe - Privilege Escalation (Metasploit)
CVE-2019-15752HIGHbajo ataquelocalwindows28 abr 2020
Docker Desktop Community Edition before 2.1.0.1 allows local users to gain privileges by placing a Trojan horse docker-c
98RIESGO
abrir
Exploit-DB
Source Engine CS:GO BuildID: 4937372 - Arbitrary Code Execution
CVE-2020-12242localmacos27 abr 2020
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in
23RIESGO
abrir
Exploit-DB
Oracle Solaris Common Desktop Environment 1.6 - Local Privilege Escalation
CVE-2020-2944HIGHlocalsolaris21 abr 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported version
41RIESGO
abrir
Exploit-DB
Neowise CarbonFTP 1.4 - Insecure Proprietary Password Encryption
CVE-2020-6857remotewindows21 abr 2020
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FT
23RIESGO
abrir
Exploit-DBVexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
CVE-2020-5847CRITICALbajo ataqueremotelinux20 abr 2020
Unraid through 6.8.0 allows Remote Code Execution.
100RIESGO
abrir
Exploit-DBVexDay Proof
Unraid 6.8.0 - Auth Bypass PHP Code Execution (Metasploit)
CVE-2020-5849HIGHbajo ataqueremotelinux20 abr 2020
Unraid 6.8.0 allows authentication bypass.
100RIESGO
abrir
Exploit-DB
Cisco IP Phone 11.7 - Denial of service (PoC)
CVE-2020-3161CRITICALbajo ataquedoshardware17 abr 2020
Cisco IP Phones Web Server Remote Code Execution and Denial of Service Vulnerability
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.