Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
78.324 exploits
GitHub PoC14
This small script helps to avoid using MetaSploit (msfconsole) during the Enterprise pentests and OSCP-like exams. Grep included function will help you to get only the important information.
CVE-2006-339204 dic 2020
Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote
60RIESGO
abrir
Exploit-DB
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
CVE-2020-28977webappsmultiple04 dic 2020
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a
28RIESGO
abrir
Exploit-DB
Wordpress Plugin Canto 1.3.0 - Blind SSRF (Unauthenticated)
CVE-2020-28978webappsmultiple04 dic 2020
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a
28RIESGO
abrir
GitHub PoC
diegojuan/CVE-2019-15107
CVE-2019-15107CRITICALbajo ataqueransomware03 dic 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC1
Scan through given ip list
CVE-2019-0708CRITICALbajo ataqueransomware03 dic 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware03 dic 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC
ActorExpose/CVE-2017-11882
CVE-2017-11882HIGHbajo ataqueransomware03 dic 2020
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Mi
100RIESGO
abrir
Exploit-DB
WonderCMS 3.1.3 - Authenticated Remote Code Execution
CVE-2020-35314webappsphp02 dic 2020
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, al
28RIESGO
abrir
Exploit-DB
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Edit Profile
CVE-2020-28687webappsmultiple02 dic 2020
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upl
28RIESGO
abrir
Exploit-DB
WonderCMS 3.1.3 - Authenticated SSRF to Remote Remote Code Execution
CVE-2020-35313webappsphp02 dic 2020
A server-side request forgery (SSRF) vulnerability in the addCustomThemePluginRepository function in index.php in Wonder
35RIESGO
abrir
Exploit-DB
WordPress Plugin Wp-FileManager 6.8 - RCE
CVE-2020-25213CRITICALbajo ataquewebappsphp02 dic 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
Exploit-DB
Anuko Time Tracker 1.19.23.5311 - No rate Limit on Password Reset functionality
CVE-2020-27423webappsphp02 dic 2020
Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial o
23RIESGO
abrir
Exploit-DB
Anuko Time Tracker 1.19.23.5311 - Password Reset leading to Account Takeover
CVE-2020-27422webappsphp02 dic 2020
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an a
23RIESGO
abrir
Exploit-DB
Artworks Gallery 1.0 - Arbitrary File Upload RCE (Authenticated) via Add Artwork
CVE-2020-28688webappsmultiple02 dic 2020
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to uplo
28RIESGO
abrir
Exploit-DB
PRTG Network Monitor 20.4.63.1412 - 'maps' Stored XSS
CVE-2020-14073webappswindows02 dic 2020
XSS exists in PRTG Network Monitor 20.1.56.1574 via crafted map properties. An attacker with Read/Write privileges can c
23RIESGO
abrir
Metasploit300
KOFFEE - Kia OFFensivE Exploit
CVE-2020-853902 dic 2020
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an atta
18RIESGO
abrir
VulnCheck XDB
local
CVE-2015-363601 dic 2020
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-3992CRITICALbajo ataqueransomware01 dic 2020
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-27950MEDIUMbajo ataque01 dic 2020
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-5544CRITICALbajo ataqueransomware01 dic 2020
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RIESGO
abrir
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2019-5544CRITICALbajo ataqueransomware01 dic 2020
OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue. VMware has evaluated the severity of
100RIESGO
abrir
GitHub PoC34
CVE-2020-27950 exploit
CVE-2020-27950MEDIUMbajo ataque01 dic 2020
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watch
68RIESGO
abrir
Exploit-DB
Wordpress Plugin EventON Calendar 3.0.5 - Reflected Cross-Site Scripting
CVE-2020-29395webappsphp01 dic 2020
The EventON plugin through 3.0.5 for WordPress allows addons/?q= XSS via the search field.
43RIESGO
abrir
Exploit-DB
Joomla! Component GMapFP 3.5 - Unauthenticated Arbitrary File Upload
CVE-2020-23972webappsphp01 dic 2020
In Joomla Component GMapFP Version J3.5 and J3.5free, an attacker can access the upload function without authenticating
50RIESGO
abrir
GitHub PoC49
Python / scapy module implementing SRVLOC/SLP protocol and scans for enabled OpenSLP services.
CVE-2020-3992CRITICALbajo ataqueransomware01 dic 2020
OpenSLP as used in VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202010401-SG, 6.5 before ESXi650-
100RIESGO
abrir
GitHub PoC1
wikiZ/cve-2014-4113
CVE-2014-4113HIGHbajo ataque30 nov 2020
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RIESGO
abrir
Exploit-DB
Rejetto HttpFileServer 2.3.x - Remote Command Execution (3)
CVE-2014-6287CRITICALbajo ataquewebappswindows30 nov 2020
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-13379CRITICALbajo ataqueransomware30 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11651CRITICALbajo ataque30 nov 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-11652MEDIUMbajo ataque30 nov 2020
An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs cla
100RIESGO
abrir
anteriorpágina 719 / 2611siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.