Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
78.324 exploits
Exploit-DB
Oracle Business Intelligence Enterprise Edition 5.5.0.0.0 / 12.2.1.3.0 / 12.2.1.4.0 - 'getPreviewImage' Directory Traversal/Local File Inclusion
CVE-2020-14864HIGHbajo ataquewebappslinux28 oct 2020
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Ins
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-14882CRITICALbajo ataque28 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
Metasploit600
Micro Focus Operations Bridge Manager / Reporter Local Privilege Escalation
CVE-2020-1185528 oct 2020
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The
18RIESGO
abrir
Exploit-DB
Blueman < 2.1.4 - Local Privilege Escalation
CVE-2020-15238HIGHlocallinux28 oct 2020
Local privilege escalation Blueman
41RIESGO
abrir
Metasploit600
Micro Focus Operations Bridge Manager / Reporter Local Privilege Escalation
CVE-2020-11858HIGH28 oct 2020
Code execution with escalated privilegesn vlnerability in Operation bridge Manager and Operations Bridge (containerized) products.
36RIESGO
abrir
Exploit-DB
Sentrifugo 3.2 - File Upload Restriction Bypass (Authenticated)
CVE-2019-15813webappsphp27 oct 2020
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RIESGO
abrir
VulnCheck XDB
local
CVE-2019-2215HIGHbajo ataque27 oct 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
GitHub PoC14
PoC for old Binder vulnerability (based on P0 exploit)
CVE-2019-2215HIGHbajo ataque27 oct 2020
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RIESGO
abrir
Metasploit600
Pulse Secure VPN gzip RCE
CVE-2020-8260HIGHbajo ataque26 oct 2020
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform
100RIESGO
abrir
GitHub PoC8
POC For CVE-2020-1481 - Jira Username Enumerator/Validator
CVE-2020-1418126 oct 2020
Affected versions of Atlassian Jira Server and Data Center allow an unauthenticated user to enumerate users via an Infor
60RIESGO
abrir
Exploit-DB
CMS Made Simple 2.1.6 - 'cntnt01detailtemplate' Server-Side Template Injection
CVE-2017-16783webappsphp26 oct 2020
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
23RIESGO
abrir
GitHub PoC
datntsec/CVE-2019-12735
CVE-2019-1273526 oct 2020
getchar.c in Vim before 8.1.1365 and Neovim before 0.3.6 allows remote attackers to execute arbitrary OS commands via th
28RIESGO
abrir
GitHub PoC2
Python exploit for CVE-2012-2982
CVE-2012-298225 oct 2020
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware23 oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC11
CVE-2020-0688 PoC
CVE-2020-0688HIGHbajo ataqueransomware23 oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
Exploit-DBVexDay Proof
Bludit 3.9.2 - Auth Bruteforce Bypass
CVE-2019-17240LOWwebappsphp23 oct 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
GitHub PoC1
PoC for apache struts 2 vuln cve-2019-0230
CVE-2019-023022 oct 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-1579HIGHbajo ataqueransomware21 oct 2020
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware21 oct 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC2
Bludit <= 3.9.2 - Authentication Bruteforce Mitigation Bypass Exploit/PoC
CVE-2019-17240LOW21 oct 2020
bl-kernel/security.class.php in Bludit 3.9.2 allows attackers to bypass a brute-force protection mechanism by using many
40RIESGO
abrir
GitHub PoC
Elsfa7-110/CVE-2019-1579
CVE-2019-1579HIGHbajo ataqueransomware21 oct 2020
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11-h1 and earlier, and PAN-OS 8.1.2 and earlier with Glob
83RIESGO
abrir
GitHub PoC
HYWZ36/CVE-2020-14645-code
CVE-2020-14645CRITICAL21 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RIESGO
abrir
Metasploit300
WordPress Loginizer log SQLi Scanner
CVE-2020-2761521 oct 2020
The Loginizer plugin before 1.6.4 for WordPress allows SQL injection (with resultant XSS), related to loginizer_login_fa
30RIESGO
abrir
GitHub PoC
puckiestyle/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware21 oct 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit600
Nagios XI 5.6.0-5.7.3 - Mibs.php Authenticated Remote Code Exection
CVE-2020-579120 oct 2020
Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi
60RIESGO
abrir
Metasploit300
Oracle Solaris SunSSH PAM parse_user_name() Buffer Overflow
CVE-2020-14871CRITICALbajo ataque20 oct 2020
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module). Supported ve
100RIESGO
abrir
Metasploit600
Nagios XI 5.5.0-5.7.3 - Snmptrap Authenticated Remote Code Exection
CVE-2020-579220 oct 2020
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user
30RIESGO
abrir
Metasploit600
NSClient++ 0.5.2.35 - Privilege escalation
CVE-2025-34078HIGH20 oct 2020
NSClient++ 0.5.2.35 Local Privilege Escalation via ExternalScripts and Web Interface
36RIESGO
abrir
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14750CRITICALbajo ataque20 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
Metasploit600
Oracle WebLogic Server Administration Console Handle RCE
CVE-2020-14882CRITICALbajo ataque20 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
anteriorpágina 726 / 2611siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.