Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.043exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
24.458 exploits
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8777webappsphp03 mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via a user profile photo,
23RIESGO
abrir
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8778webappsphp03 mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via an uploaded document,
23RIESGO
abrir
Exploit-DB
Alfresco 5.2.4 - Persistent Cross-Site Scripting
CVE-2020-8776webappsphp03 mar 2020
Alfresco Enterprise before 5.2.7 and Alfresco Community before 6.2.0 (rb65251d6-b368) has XSS via the URL property of a
23RIESGO
abrir
Exploit-DB
Joplin Desktop 1.0.184 - Cross-Site Scripting
CVE-2020-9038webappsmultiple02 mar 2020
Joplin through 1.0.184 allows Arbitrary File Read via XSS.
23RIESGO
abrir
Exploit-DB
CA Unified Infrastructure Management Nimsoft 7.80 - Remote Buffer Overflow
CVE-2020-8012remotewindows02 mar 2020
CA Unified Infrastructure Management (Nimsoft/UIM) 20.1, 20.3.x, and 9.20 and below contains a buffer overflow vulnerabi
60RIESGO
abrir
Exploit-DB
TP LINK TL-WR849N - Remote Code Execution
CVE-2020-9374webappshardware02 mar 2020
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploit
35RIESGO
abrir
Exploit-DB
Microsoft Exchange 2019 15.2.221.12 - Authenticated Remote Code Execution
CVE-2020-0688HIGHbajo ataqueransomwareremotewindows02 mar 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Exploit-DB
WordPress Plugin Tutor LMS 1.5.3 - Cross-Site Request Forgery (Add User)
CVE-2020-8615webappsphp02 mar 2020
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a
38RIESGO
abrir
Exploit-DB
Intelbras Wireless N 150Mbps WRN240 - Authentication Bypass (Config Upload)
CVE-2019-19142webappshardware02 mar 2020
Intelbras WRN240 devices do not require authentication to replace the firmware via a POST request to the incoming/Firmwa
23RIESGO
abrir
Exploit-DB
TL-WR849N 0.9.1 4.16 - Authentication Bypass (Upload Firmware)
CVE-2019-19143webappshardware02 mar 2020
TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi
23RIESGO
abrir
Exploit-DB
qdPM < 9.1 - Remote Code Execution
CVE-2020-7246webappsmultiple28 feb 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir
Exploit-DB
OpenSMTPD < 6.6.3p1 - Local Privilege Escalation + Remote Code Execution
CVE-2020-8794remoteopenbsd26 feb 2020
OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for mult
60RIESGO
abrir
Exploit-DB
OpenSMTPD 6.6.3 - Arbitrary File Read
CVE-2020-8793remotelinux26 feb 2020
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combi
23RIESGO
abrir
Exploit-DB
ManageEngine EventLog Analyzer 10.0 - Information Disclosure
CVE-2019-19774webappsjava24 feb 2020
An issue was discovered in Zoho ManageEngine EventLog Analyzer 10.0 SP1 before Build 12110. By running "select hostdetai
28RIESGO
abrir
Exploit-DB
Avaya IP Office Application Server 11.0.0.0 - Reflective Cross-Site Scripting
CVE-2019-7004MEDIUMwebappshardware24 feb 2020
Avaya IP Office XSS Vulnerability
33RIESGO
abrir
Exploit-DBVexDay Proof
Android Binder - Use-After-Free (Metasploit)
CVE-2019-2215HIGHbajo ataquelocalandroid24 feb 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
98RIESGO
abrir
Exploit-DB
Go SSH servers 0.0.2 - Denial of Service (PoC)
CVE-2020-9283doslinux24 feb 2020
golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the
28RIESGO
abrir
Exploit-DBVexDay Proof
Apache James Server 2.3.2 - Insecure User Creation Arbitrary File Write (Metasploit)
CVE-2015-7611remotelinux24 feb 2020
Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary syst
50RIESGO
abrir
Exploit-DB
Apache Tomcat - AJP 'Ghostcat File Read/Inclusion
CVE-2020-1938CRITICALbajo ataquewebappsmultiple20 feb 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
Exploit-DB
MSI Packages Symbolic Links Processing - Windows 10 Privilege Escalation
CVE-2020-0683HIGHbajo ataquelocalwindows17 feb 2020
An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'W
71RIESGO
abrir
Exploit-DBVexDay Proof
Anviz CrossChex - Buffer Overflow (Metasploit)
CVE-2019-12518remotewindows17 feb 2020
Anviz CrossChex access control management software 4.3.8.0 and 4.3.12 is vulnerable to a buffer overflow vulnerability.
50RIESGO
abrir
Exploit-DB
PANDORAFMS 7.0 - Authenticated Remote Code Execution
CVE-2020-8947webappsphp13 feb 2020
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metac
28RIESGO
abrir
Exploit-DBVexDay Proof
HP System Event Utility - Local Privilege Escalation
CVE-2019-18915localwindows12 feb 2020
A potential security vulnerability has been identified with certain versions of HP System Event Utility prior to version
23RIESGO
abrir
Exploit-DB
CHIYU BF430 TCP IP Converter - Stored Cross-Site Scripting
CVE-2020-8839webappscgi11 feb 2020
Stored XSS was discovered on CHIYU BF-430 232/485 TCP/IP Converter devices before 1.16.00, as demonstrated by the /if.cg
23RIESGO
abrir
Exploit-DBVexDay Proof
OpenSMTPD 6.4.0 < 6.6.1 - Local Privilege Escalation + Remote Code Execution
CVE-2020-7247CRITICALbajo ataqueremoteopenbsd11 feb 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
Exploit-DB
Vanilla Forums 2.6.3 - Persistent Cross-Site Scripting
CVE-2020-8825webappsphp11 feb 2020
index.php?p=/dashboard/settings/branding in Vanilla 2.6.3 allows stored XSS.
23RIESGO
abrir
Exploit-DB
WordPress Plugin LearnDash LMS 3.1.2 - Reflective Cross-Site Scripting
CVE-2020-7108webappsphp10 feb 2020
The LearnDash LMS plugin before 3.1.2 for WordPress allows XSS via the ld-profile search field.
23RIESGO
abrir
Exploit-DB
Forcepoint WebSecurity 8.5 - Reflective Cross-Site Scripting
CVE-2019-6146webappsmultiple10 feb 2020
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host heade
23RIESGO
abrir
Exploit-DBVexDay Proof
Ricoh Driver - Privilege Escalation (Metasploit)
CVE-2019-19363localwindows10 feb 2020
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RIESGO
abrir
Exploit-DBVexDay Proof
OpenSMTPD - MAIL FROM Remote Code Execution (Metasploit)
CVE-2020-7247CRITICALbajo ataqueremotelinux10 feb 2020
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.