Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.324exploits catalogados
36.054CVEs con explotación pública
24.695probados en laboratorio
78.324 exploits
Metasploit600
FlexDotnetCMS Arbitrary ASP File Upload
CVE-2020-2738628 sep 2020
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and e
40RIESGO
abrir
Exploit-DB
Joplin 1.0.245 - Arbitrary Code Execution (PoC)
CVE-2020-15930webappsmultiple28 sep 2020
An XSS issue in Joplin desktop 1.0.190 to 1.0.245 allows arbitrary code execution via a malicious HTML embed tag.
23RIESGO
abrir
GitHub PoC24
Just basic scanner abusing CVE-2020-3452 to enumerate the standard files accessible in the Web Directory of the CISCO ASA applicances.
CVE-2020-3452HIGHbajo ataque28 sep 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
Exploit-DB
MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
CVE-2020-17382localwindows28 sep 2020
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware26 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC5
striveben/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware26 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-3433HIGHbajo ataqueransomware25 sep 2020
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware25 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
local
CVE-2019-0808HIGHbajo ataque25 sep 2020
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RIESGO
abrir
GitHub PoC42
PoCs and technical analysis of three vulnerabilities found on Cisco AnyConnect for Windows: CVE-2020-3433, CVE-2020-3434 and CVE-2020-3435
CVE-2020-3433HIGHbajo ataqueransomware25 sep 2020
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RIESGO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHbajo ataque25 sep 2020
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RIESGO
abrir
Metasploit600
HorizontCMS Arbitrary PHP File Upload
CVE-2020-2738724 sep 2020
An unrestricted file upload issue in HorizontCMS through 1.0.0-beta allows an authenticated remote attacker (with access
23RIESGO
abrir
GitHub PoC
CVE 2020-1472 Script de validación
CVE-2020-1472MEDIUMbajo ataqueransomware24 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
This repository holds the advisory, exploits and vulnerable software of the CVE-2020-15492
CVE-2020-1549224 sep 2020
An issue was discovered in INNEO Startup TOOLS 2017 M021 12.0.66.3784 through 2018 M040 13.0.70.3804. The sut_srv.exe we
28RIESGO
abrir
GitHub PoC1
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, City
CVE-2020-2527023 sep 2020
PHPGurukul hostel-management-system 2.1 allows XSS via Guardian Name, Guardian Relation, Guardian Contact no, Address, o
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12617HIGHbajo ataque23 sep 2020
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTT
100RIESGO
abrir
Exploit-DB
Comodo Unified Threat Management Web Console 2.7.0 - Remote Code Execution
CVE-2018-17431webappsmultiple22 sep 2020
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware21 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
t31m0/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware21 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
BlackCat CMS 1.3.6 - Cross-Site Request Forgery
CVE-2020-25453webappsphp21 sep 2020
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote
23RIESGO
abrir
Exploit-DB
Mida eFramework 2.9.0 - Back Door Access
CVE-2020-15921webappshardware21 sep 2020
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric
28RIESGO
abrir
Metasploit600
Micro Focus Operations Bridge Reporter shrboadmin default password
CVE-2020-1185721 sep 2020
An Authorization Bypass vulnerability on Micro Focus Operation Bridge Reporter, affecting version 10.40 and earlier. The
23RIESGO
abrir
VulnCheck XDB
local
CVE-2020-1048HIGH21 sep 2020
Windows Print Spooler Elevation of Privilege Vulnerability
61RIESGO
abrir
GitHub PoC
johnpathe/zerologon-cve-2020-1472-notes
CVE-2020-1472MEDIUMbajo ataqueransomware20 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
hectorgie/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware19 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware19 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware19 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
A simple implementation/code smash of a bunch of other repos
CVE-2020-1472MEDIUMbajo ataqueransomware19 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC10
CVE-2020-1472复现时使用的py文件整理打包
CVE-2020-1472MEDIUMbajo ataqueransomware18 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11699webappsmultiple18 sep 2020
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php woul
23RIESGO
abrir
anteriorpágina 730 / 2611siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.