Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.295exploits catalogados
36.048CVEs con explotación pública
24.695probados en laboratorio
78.295 exploits
GitHub PoC7
quick'n'dirty automated checks for potential exploitation of CVE-2020-1472 (aka ZeroLogon), using leading artifects in determining an actual exploitation of CVE-2020-1472. requires admin access to the DCs
CVE-2020-1472MEDIUMbajo ataqueransomware07 ene 2021
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC5
uzzzval/CVE-2020-17530
CVE-2020-17530CRITICALbajo ataque07 ene 2021
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC3
Python implementation of Roundcube LFI (CVE-2017-16651)
CVE-2017-16651HIGHbajo ataque06 ene 2021
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RIESGO
abrir
Exploit-DBVexDay Proof
Gitea 1.7.5 - Remote Code Execution
CVE-2019-11229webappsmultiple06 ene 2021
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to rem
35RIESGO
abrir
Exploit-DBVexDay Proof
PaperStream IP (TWAIN) 1.42.0.5685 - Local Privilege Escalation
CVE-2018-16156localwindows06 ene 2021
In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes u
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-798006 ene 2021
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
60RIESGO
abrir
VulnCheck XDB
local
CVE-2017-16651HIGHbajo ataque06 ene 2021
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized access to arbitrary file
98RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1751806 ene 2021
Apache Flink directory traversal attack: remote file writing through the REST API
50RIESGO
abrir
Exploit-DB
IPeakCMS 3.5 - Boolean-based blind SQLi
CVE-2021-3018webappsmultiple06 ene 2021
ipeak Infosystems ibexwebCMS (aka IPeakCMS) 3.5 is vulnerable to an unauthenticated Boolean-based SQL injection via the
43RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALbajo ataque06 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALbajo ataque06 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-17519CRITICALbajo ataque06 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC48
Apache Flink 目录遍历漏洞批量检测 (CVE-2020-17519)
CVE-2020-17519CRITICALbajo ataque06 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC1
QmF0c3UK/CVE-2020-17519
CVE-2020-17519CRITICALbajo ataque06 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC3
Apache Flink Directory Traversal (CVE-2020-17519) Nmap NSE Script
CVE-2020-17519CRITICALbajo ataque06 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
Exploit-DBVexDay Proof
Sonatype Nexus 3.21.1 - Remote Code Execution (Authenticated)
CVE-2020-10199HIGHbajo ataquewebappsjava06 ene 2021
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
100RIESGO
abrir
Exploit-DB
Fluentd TD-agent plugin 4.0.1 - Insecure Folder Permission
CVE-2020-28169localwindows05 ene 2021
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-10148CRITICALbajo ataque05 ene 2021
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RIESGO
abrir
Exploit-DBVexDay Proof
Klog Server 2.4.1 - Command Injection (Unauthenticated)
CVE-2020-35729webappsphp05 ene 2021
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
60RIESGO
abrir
GitHub PoC10
SolarWinds Orion API 远程代码执行漏洞批量检测脚本
CVE-2020-10148CRITICALbajo ataque05 ene 2021
SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands
100RIESGO
abrir
Exploit-DB
IncomCMS 2.0 - Insecure File Upload
CVE-2020-29597webappsmultiple05 ene 2021
IncomCMS 2.0 has a modules/uploader/showcase/script.php insecure file upload vulnerability. This vulnerability allows un
60RIESGO
abrir
GitHub PoC99
CISCO CVE-2020-3452 Scanner & Exploiter
CVE-2020-3452HIGHbajo ataque05 ene 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
Metasploit300
Apache Flink JobManager Traversal
CVE-2020-17519CRITICALbajo ataque05 ene 2021
Apache Flink directory traversal attack: reading remote files through the REST API
100RIESGO
abrir
GitHub PoC1
andyfeili/CVE-2014-4688
CVE-2014-468805 ene 2021
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHbajo ataque05 ene 2021
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
Exploit-DB
Mantis Bug Tracker 2.24.3 - 'access' SQL Injection
CVE-2020-28413MEDIUMwebappsphp04 ene 2021
In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the A
33RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware04 ene 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Exploit-DB
Advanced Comment System 1.0 - 'ACS_path' Path Traversal
CVE-2020-35598webappsphp04 ene 2021
ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=.
43RIESGO
abrir
GitHub PoC21
Remote Code Execution on Microsoft Exchange Server through fixed cryptographic keys
CVE-2020-0688HIGHbajo ataqueransomware04 ene 2021
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC16
Scanner for Zyxel products which are potentially vulnerable due to an undocumented user account (CVE-2020-29583)
CVE-2020-29583CRITICALbajo ataque04 ene 2021
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The p
100RIESGO
abrir
anteriorpágina 713 / 2610siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.