Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.325exploits catalogados
36.055CVEs con explotación pública
24.695probados en laboratorio
78.325 exploits
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11804webappsmultiple18 sep 2020
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page ma
23RIESGO
abrir
GitHub PoC10
CVE-2020-1472复现时使用的py文件整理打包
CVE-2020-1472MEDIUMbajo ataqueransomware18 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11700webappsmultiple18 sep 2020
An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.
23RIESGO
abrir
Exploit-DB
SpamTitan 7.07 - Remote Code Execution (Authenticated)
CVE-2020-11699webappsmultiple18 sep 2020
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php woul
23RIESGO
abrir
Exploit-DB
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
CVE-2019-15715webappsphp18 sep 2020
MantisBT before 1.3.20 and 2.22.1 allows Post Authentication Command Injection, leading to Remote Code Execution.
35RIESGO
abrir
Exploit-DB
Mantis Bug Tracker 2.3.0 - Remote Code Execution (Unauthenticated)
CVE-2017-7615webappsphp18 sep 2020
MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value
60RIESGO
abrir
GitHub PoC
Scripts to verify and execute CVE-2019-14287 as part of Research
CVE-2019-1428718 sep 2020
In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and se
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware18 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit600
Sophos UTM WebAdmin SID Command Injection
CVE-2020-25223CRITICALbajo ataque18 sep 2020
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware17 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware17 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
pwn3z/CVE-2019-11510-PulseVPN
CVE-2019-11510CRITICALbajo ataqueransomware17 sep 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-11510CRITICALbajo ataqueransomware17 sep 2020
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthent
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-0796CRITICALbajo ataqueransomware17 sep 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC1
pwn3z/CVE-2018-13379-FortinetVPN
CVE-2018-13379CRITICALbajo ataqueransomware17 sep 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-13379CRITICALbajo ataqueransomware17 sep 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
GitHub PoC70
rsmudge/CVE-2020-0796-BOF
CVE-2020-0796CRITICALbajo ataqueransomware17 sep 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC114
PoC exploits for CVE-2020-17382
CVE-2020-1738217 sep 2020
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RIESGO
abrir
Exploit-DB
Microsoft SQL Server Reporting Services 2016 - Remote Code Execution
CVE-2020-0618CRITICALbajo ataqueransomwareremotewindows17 sep 2020
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
GitHub PoC61
Test script for CVE-2020-1472 for both RPC/TCP and RPC/SMB
CVE-2020-1472MEDIUMbajo ataqueransomware17 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC2
cve-2020-1472_Tool collection
CVE-2020-1472MEDIUMbajo ataqueransomware16 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
Zabbix Template to monitor for Windows Event Viewer event's related to Netlogon Elevation of Privilege Vulnerability - CVE-2020-1472. Monitors event ID's 5827, 5828 & 5829. See: https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware16 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
Piwigo 2.10.1 - Cross Site Scripting
CVE-2020-9467webappsphp16 sep 2020
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
28RIESGO
abrir
GitHub PoC2
CVE-2020-1472 - Zero Logon vulnerability Python implementation
CVE-2020-1472MEDIUMbajo ataqueransomware16 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware16 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware16 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC
FaFcFF41/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware16 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
https://github.com/dirkjanm/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware16 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
[CVE-2020-1472] Netlogon Remote Protocol Call (MS-NRPC) Privilege Escalation (Zerologon)
CVE-2020-1472MEDIUMbajo ataqueransomware16 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware16 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
anteriorpágina 731 / 2611siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.