Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
78.324 exploits
VulnCheck XDB
remote-with-credentials
CVE-2017-1721517 nov 2020
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
35RIESGO
abrir
GitHub PoC
windows.vm
CVE-2019-3396CRITICALbajo ataqueransomware17 nov 2020
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
DHCP exploitation with DynoRoot (CVE-2018-1111)
CVE-2018-1111HIGH17 nov 2020
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir
GitHub PoC9
A Remote Code Execution (RCE) exploit for Huawei HG532d based on CVE-2017-17215 vulnerability. Modded from original PoC code from exploit-db.com
CVE-2017-1721517 nov 2020
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
35RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 11 - Use-After-Free
CVE-2020-0674HIGHbajo ataquelocalwindows17 nov 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
Exploit-DB
Aerospike Database 5.1.0.3 - OS Command Execution
CVE-2020-13151remotemultiple17 nov 2020
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RIESGO
abrir
GitHub PoC
BabyTeam1024/CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque17 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-820917 nov 2020
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware16 nov 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-4852CRITICALbajo ataque16 nov 2020
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
Metasploit600
Monitorr unauthenticated Remote Code Execution (RCE)
CVE-2020-2887116 nov 2020
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the s
40RIESGO
abrir
GitHub PoC1
b1ack0wl/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware16 nov 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
nex1less/CVE-2015-4852
CVE-2015-4852CRITICALbajo ataque16 nov 2020
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-15227HIGH15 nov 2020
Remote Code Execution vulnerability
68RIESGO
abrir
Metasploit600
WordPress AIT CSV Import Export Unauthenticated Remote Code Execution
CVE-2020-36849CRITICAL14 nov 2020
AIT CSV import/export <= 3.0.3 - Unauthenticated Arbitrary File Upload
43RIESGO
abrir
GitHub PoC12
Hikvision IP camera access bypass exploit, developed by golang.
CVE-2017-7921CRITICALbajo ataque13 nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC57
Exploit for Laravel Remote Code Execution with API_KEY (CVE-2018-15133)
CVE-2018-15133HIGHbajo ataque13 nov 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC
rvermeulen/apache-struts-cve-2017-9805
CVE-2017-9805HIGHbajo ataque13 nov 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
GitHub PoC1
CVE-2020-25213 Wordpress File Manager 6.7 Plugin 0day exploit
CVE-2020-25213CRITICALbajo ataque13 nov 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
Exploit-DB
OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
CVE-2020-15478webappsphp13 nov 2020
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
23RIESGO
abrir
Exploit-DB
October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
CVE-2020-5295MEDIUMwebappsphp13 nov 2020
Local File read vulnerability in OctoberCMS
33RIESGO
abrir
Exploit-DB
Touchbase.io 1.10 - Stored Cross Site Scripting
CVE-2020-26218HIGHwebappsmultiple13 nov 2020
HTML Injection in touchbase.ai
41RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
CVE-2020-1938CRITICALbajo ataquewebappsmultiple13 nov 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-15133HIGHbajo ataque13 nov 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALbajo ataque13 nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque12 nov 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-7921CRITICALbajo ataque12 nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC2
A very simple buffer overflow using CVE-2013-4730 against PCman's FTP server
CVE-2013-473012 nov 2020
Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USE
50RIESGO
abrir
GitHub PoC3
zavke/CVE-2020-10189-ManageEngine
CVE-2020-10189CRITICALbajo ataque12 nov 2020
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RIESGO
abrir
GitHub PoC
MuirlandOracle/CVE-2014-6271-IPFire
CVE-2014-6271CRITICALbajo ataque12 nov 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
anteriorpágina 722 / 2611siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.