Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
78.324 exploits
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALbajo ataque10 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-17144HIGHbajo ataque09 dic 2020
Microsoft Exchange Remote Code Execution Vulnerability
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-17530CRITICALbajo ataque09 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-17144HIGHbajo ataque09 dic 2020
Microsoft Exchange Remote Code Execution Vulnerability
83RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2014-0160HIGHbajo ataque09 dic 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed
CVE-2014-0160HIGHbajo ataque09 dic 2020
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RIESGO
abrir
GitHub PoC
WildfootW/CVE-2018-15473_OpenSSH_7.7
CVE-2018-15473MEDIUM09 dic 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
Exploit-DB
SmarterMail Build 6985 - Remote Code Execution
CVE-2019-7214remotewindows09 dic 2020
SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker co
60RIESGO
abrir
GitHub PoC
WildfootW/CVE-2007-2447_Samba_3.0.25rc3
CVE-2007-244709 dic 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC157
Exchange2010 authorized RCE
CVE-2020-17144HIGHbajo ataque09 dic 2020
Microsoft Exchange Remote Code Execution Vulnerability
83RIESGO
abrir
GitHub PoC64
ka1n4t/CVE-2020-17530
CVE-2020-17530CRITICALbajo ataque09 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC1
Apache Struts2框架是一个用于开发Java EE网络应用程序的Web框架。Apache Struts于2020年12月08日披露 S2-061 Struts 远程代码执行漏洞(CVE-2020-17530),在使用某些tag等情况下可能存在OGNL表达式注入漏洞,从而造成远程代码执行,风险极大。提醒我校Apache Struts用户尽快采取安全措施阻止漏洞攻击。
CVE-2020-17530CRITICALbajo ataque09 dic 2020
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
GitHub PoC157
weaponized tool for CVE-2020-17144
CVE-2020-17144HIGHbajo ataque09 dic 2020
Microsoft Exchange Remote Code Execution Vulnerability
83RIESGO
abrir
GitHub PoC
Remote code execution in Mediawiki Score
CVE-2020-29007CRITICAL08 dic 2020
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of
48RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-7961CRITICALbajo ataque08 dic 2020
Deserialization of Untrusted Data in Liferay Portal prior to 7.2.1 CE GA2 allows remote attackers to execute arbitrary c
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-1472MEDIUMbajo ataqueransomware08 dic 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2019-261808 dic 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
28RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALbajo ataqueransomware08 dic 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-0796CRITICALbajo ataqueransomware08 dic 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-0796CRITICALbajo ataqueransomware08 dic 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
Metasploit600
APISIX Admin API default access token RCE
CVE-2022-24112CRITICALbajo ataque07 dic 2020
apisix/batch-requests plugin allows overwriting the X-REAL-IP header
100RIESGO
abrir
Exploit-DB
Druva inSync Windows Client 6.6.3 - Local Privilege Escalation (PowerShell)
CVE-2020-5752localwindows07 dic 2020
Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitra
38RIESGO
abrir
Metasploit600
APISIX Admin API default access token RCE
CVE-2020-1394507 dic 2020
In Apache APISIX, the user enabled the Admin API and deleted the Admin API access IP restriction rules. Eventually, the
40RIESGO
abrir
Metasploit300
WordPress Easy WP SMTP Password Reset
CVE-2020-3523406 dic 2020
The easy-wp-smtp plugin before 1.4.4 for WordPress allows Administrator account takeover, as exploited in the wild in De
30RIESGO
abrir
GitHub PoC1
PoC for CVE: 2017-5638 - Apache Struts2 S2-045
CVE-2017-5638CRITICALbajo ataqueransomware06 dic 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-5638CRITICALbajo ataqueransomware06 dic 2020
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
GitHub PoC
Exploit for the vulnerability CVE-2007-2447
CVE-2007-244706 dic 2020
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RIESGO
abrir
GitHub PoC
[qdPM < 9.1 - Remote Code Execution](https://www.exploit-db.com/exploits/48146)
CVE-2020-724605 dic 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir
Exploit-DB
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
CVE-2020-28977webappsmultiple04 dic 2020
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a
28RIESGO
abrir
Exploit-DB
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
CVE-2020-28976webappsmultiple04 dic 2020
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make
43RIESGO
abrir
anteriorpágina 718 / 2611siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.