Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
78.324 exploits
VulnCheck XDB
infoleak
CVE-2020-5902CRITICALbajo ataqueransomware14 oct 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-2883CRITICALbajo ataque14 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
GitHub PoC2
FancyDoesSecurity/CVE-2020-2883
CVE-2020-2883CRITICALbajo ataque14 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
Metasploit600
Microsoft SharePoint Server-Side Include and ViewState RCE
CVE-2020-16952HIGH13 oct 2020
Microsoft SharePoint Remote Code Execution Vulnerability
58RIESGO
abrir
GitHub PoC10
BlueBorne Exploits & Framework This repository contains a PoC code of various exploits for the BlueBorne vulnerabilities. Under 'android' exploits for the Android RCE vulnerability (CVE-2017-0781), and the SDP Information leak vulnerability (CVE-2017-0785) can be found. Under 'linux-bluez' exploits for the Linux-RCE vulnerability (CVE-2017-1000251) can be found (for Amazon Echo, and Samsung Gear S3). Under 'l2cap_infra' a general testing framework to send and receive raw l2cap messages (using scapy) can be found. Under 'nRF24_BDADDR_Sniffer' a tool to capture bluetooth mac addresses (BDADDR) over the air, using a nRF24L01 chip For more details on BlueBorne, you may read the full technical white paper available here: https://www.armis.com/blueborne/ In addition a several detailed blog posts on the exploitation of these vulnerability can be found here: https://www.armis.com/blog/ =============== Dependencies:
CVE-2017-078112 oct 2020
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
Exploit-DB
Cisco ASA and FTD 9.6.4.42 - Path Traversal
CVE-2020-3452HIGHbajo ataquewebappshardware12 oct 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC2
shanfenglan/cve-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware10 oct 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC58
https://medium.com/@mansoorr/exploiting-cve-2020-25213-wp-file-manager-wordpress-plugin-6-9-3f79241f0cd8
CVE-2020-25213CRITICALbajo ataque10 oct 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware10 oct 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-15227HIGH10 oct 2020
Remote Code Execution vulnerability
68RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware10 oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALbajo ataque10 oct 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware10 oct 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALbajo ataqueransomware10 oct 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC4
n3m1sys/CVE-2018-16763-Exploit-Python3
CVE-2018-1676310 oct 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-15227HIGH09 oct 2020
Remote Code Execution vulnerability
68RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware09 oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
GitHub PoC2
提供单个或批量URL扫描是否存在CVE-2022-22954功能
CVE-2022-22954CRITICALbajo ataqueransomware09 oct 2020
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
Exploit-DB
Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
CVE-2019-19493webappsphp09 oct 2020
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, lea
23RIESGO
abrir
GitHub PoC5
Typesetter CMS文件上传漏洞环境
CVE-2020-2579009 oct 2020
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RIESGO
abrir
Exploit-DB
D-Link DSR-250N 3.12 - Denial of Service (PoC)
CVE-2020-26567webappshardware08 oct 2020
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed
28RIESGO
abrir
GitHub PoC7
EternalBlue is a well-known SMB exploit created by the NSA to attack various versions of Windows, including Windows 7. Etern-Blue-Windows-7-Checker will basically send SMB packets to a host to see if that Windows host machine is vulnerable to the EternalBlue exploit (CVE-2017-0143).
CVE-2017-0143HIGHbajo ataqueransomware07 oct 2020
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
GitHub PoC
Bludit 3.9.2 - Remote command execution - CVE-2019-16113
CVE-2019-1611307 oct 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware07 oct 2020
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware07 oct 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
Metasploit600
Gitea Git Hooks Remote Code Execution
CVE-2020-1414407 oct 2020
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer envir
40RIESGO
abrir
Metasploit600
Gogs Git Hooks Remote Code Execution
CVE-2020-1586707 oct 2020
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privile
40RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-3088CRITICALbajo ataque06 oct 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-999506 oct 2020
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware05 oct 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
anteriorpágina 728 / 2611siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.