Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
78.324 exploits
GitHub PoC
cve-2019-0708 vulnerablility scanner
CVE-2019-0708CRITICALbajo ataqueransomware17 dic 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Exploit-DB
Nxlog Community Edition 2.10.2150 - DoS (Poc)
CVE-2020-35488dosmultiple17 dic 2020
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RIESGO
abrir
Exploit-DB
Cisco ASA 9.14.1.10 and FTD 6.6.0.1 - Path Traversal (2)
CVE-2020-3452HIGHbajo ataquewebappshardware15 dic 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC
Apache Solr 1.4 Injection to get a shell
CVE-2019-17558HIGHbajo ataque15 dic 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
Metasploit600
HPE Systems Insight Manager AMF Deserialization RCE
CVE-2020-720015 dic 2020
A potential security vulnerability has been identified in HPE Systems Insight Manager (SIM) version 7.6. The vulnerabili
40RIESGO
abrir
Exploit-DB
Solaris SunSSH 11.0 x86 - libpam Remote Root
CVE-2020-14871CRITICALbajo ataqueremotesolaris15 dic 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RIESGO
abrir
GitHub PoC1
GuillaumePetit84/CVE-2020-35488
CVE-2020-3548815 dic 2020
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote attackers to cause a denial of
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALbajo ataque14 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC9
Fortinet FortiOS路径遍历漏洞 (CVE-2018-13379)批量检测脚本
CVE-2018-13379CRITICALbajo ataqueransomware14 dic 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Exploit-DB
GitLab 11.4.7 - Remote Code Execution (Authenticated) (1)
CVE-2018-19571webappsruby14 dic 2020
GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an
28RIESGO
abrir
Exploit-DB
GitLab 11.4.7 - Remote Code Execution (Authenticated) (1)
CVE-2018-19585webappsruby14 dic 2020
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection
28RIESGO
abrir
GitHub PoC7
CVE-2020-17530-strust2-061
CVE-2020-17530CRITICALbajo ataque14 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
Exploit-DB
Jenkins 2.235.3 - 'X-Forwarded-For' Stored XSS
CVE-2020-2231webappsjava14 dic 2020
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via '
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-13379CRITICALbajo ataqueransomware14 dic 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHbajo ataque13 dic 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHbajo ataque13 dic 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC29
S2-061 CVE-2020-17530
CVE-2020-17530CRITICALbajo ataque13 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALbajo ataque13 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC2
CVE-2014-0160 OpenSSL Heartbleed Proof of Concept
CVE-2014-0160HIGHbajo ataque13 dic 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC26
cygenta/CVE-2020-3452
CVE-2020-3452HIGHbajo ataque13 dic 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
Metasploit300
WordPress Total Upkeep Unauthenticated Backup Downloader
CVE-2020-36848HIGH12 dic 2020
Total Upkeep by BoldGrid <= 1.14.9 - Unauthenticated Backup Download
36RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.06 or lower - Unauthenticated Remote Code Execution
CVE-2020-2818812 dic 2020
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inje
40RIESGO
abrir
Metasploit600
TerraMaster TOS 4.2.06 or lower - Unauthenticated Remote Code Execution
CVE-2020-3566512 dic 2020
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in
60RIESGO
abrir
GitHub PoC
MasterSploit/CVE-2020-0787-BitsArbitraryFileMove-master
CVE-2020-0787HIGHbajo ataqueransomware11 dic 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir
GitHub PoC
MasterSploit/CVE-2020-0787
CVE-2020-0787HIGHbajo ataqueransomware11 dic 2020
An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperl
98RIESGO
abrir
Exploit-DB
Jenkins 2.235.3 - 'tooltip' Stored Cross-Site Scripting
CVE-2020-2229webappsjava11 dic 2020
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a sto
23RIESGO
abrir
Exploit-DB
Jenkins 2.235.3 - 'Description' Stored XSS
CVE-2020-2230webappsjava11 dic 2020
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, resulting in
45RIESGO
abrir
GitHub PoC9
S2-059(CVE-2019-0230)
CVE-2019-023011 dic 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir
Exploit-DB
Rukovoditel 2.6.1 - RCE (1)
CVE-2020-11819webappsphp11 dic 2020
In Rukovoditel 2.5.2, an attacker may inject an arbitrary .php file location instead of a language file and thus achieve
28RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALbajo ataque10 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
anteriorpágina 717 / 2611siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.