Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
78.324 exploits
Exploit-DB
GitLab 11.4.7 - RCE (Authenticated) (2)
CVE-2018-19585webappsruby24 dic 2020
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection
28RIESGO
abrir
GitHub PoC
Insecure Folder permission that lead to privilege escalation
CVE-2020-2816924 dic 2020
The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory
23RIESGO
abrir
GitHub PoC
Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840
CVE-2019-1284023 dic 2020
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RIESGO
abrir
GitHub PoC
Webmin Exploit Scanner CVE-2020-35606 CVE-2019-12840
CVE-2020-3560623 dic 2020
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex
28RIESGO
abrir
GitHub PoC
SaharAttackit/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware23 dic 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware23 dic 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC4
Supervisord远程命令执行漏洞脚本
CVE-2017-1161022 dic 2020
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-1161022 dic 2020
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows rem
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1394222 dic 2020
Remote Code Execution in Apache Unomi
50RIESGO
abrir
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'To OLAP' Reflected XSS
CVE-2020-20141webappsmultiple21 dic 2020
Cross Site Scripting (XSS) vulnerability in the To OLAP (XMLA) component Under the Connect menu in Flexmonster Pivot Tab
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-15133HIGHbajo ataque21 dic 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote Report' Reflected XSS
CVE-2020-20140webappsmultiple21 dic 2020
Cross Site Scripting (XSS) vulnerability in Remote Report component under the Open menu in Flexmonster Pivot Table & Cha
23RIESGO
abrir
GitHub PoC35
Laravel RCE exploit. CVE-2018-15133
CVE-2018-15133HIGHbajo ataque21 dic 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
Exploit-DB
SCO Openserver 5.0.7 - 'outputform' Command Injection
CVE-2020-25494webappssco21 dic 2020
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou
35RIESGO
abrir
Exploit-DB
Spiceworks 7.5 - HTTP Header Injection
CVE-2020-25901webappswindows21 dic 2020
Host Header Injection in Spiceworks 7.5.7.0 allowing the attacker to render arbitrary links that point to a malicious we
23RIESGO
abrir
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'Remote JSON' Reflected XSS
CVE-2020-20139webappsmultiple21 dic 2020
Cross Site Scripting (XSS) vulnerability in the Remote JSON component Under the Connect menu in Flexmonster Pivot Table
23RIESGO
abrir
Exploit-DB
SCO Openserver 5.0.7 - 'section' Reflected XSS
CVE-2020-25495webappssco21 dic 2020
A reflected Cross-site scripting (XSS) vulnerability in Xinuo (formerly SCO) Openserver version 5 and 6 allows remote at
38RIESGO
abrir
Exploit-DB
Flexmonster Pivot Table & Charts 2.7.17 - 'To remote CSV' Reflected XSS
CVE-2020-20142webappsmultiple21 dic 2020
Cross Site Scripting (XSS) vulnerability in the "To Remote CSV" component under "Open" Menu in Flexmonster Pivot Table &
23RIESGO
abrir
GitHub PoC2
Collection of PoCs created for SmarterMail < Build 6985 RCE
CVE-2019-721420 dic 2020
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque20 dic 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
GitHub PoC2
DirtyCOW Exploit for Android
CVE-2016-5195HIGHbajo ataque20 dic 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0787HIGHbajo ataqueransomware20 dic 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir
GitHub PoC
https://github.com/awakened1712/CVE-2019-11932://github.com/awakened1712/CVE-2019-11932
CVE-2019-1193220 dic 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
GitHub PoC1
POC for CVE-2018-0114 written in Go
CVE-2018-011420 dic 2020
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RIESGO
abrir
Metasploit600
Nagios XI Prior to 5.8.0 - Plugins Filename Authenticated Remote Code Exection
CVE-2020-3557819 dic 2020
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2019-0752HIGHbajo ataqueransomware18 dic 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
GitHub PoC2
edxsh/CVE-2019-0752
CVE-2019-0752HIGHbajo ataqueransomware18 dic 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
GitHub PoC
(cve-2020-17530) struts2_s2-061 freemarker_RCE testscript
CVE-2020-17530CRITICALbajo ataque18 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
Exploit-DB
FRITZ!Box 7.20 - DNS Rebinding Protection Bypass
CVE-2020-26887remotehardware18 dic 2020
FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALbajo ataque18 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
anteriorpágina 716 / 2611siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.