Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.331exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
78.331 exploits
VulnCheck XDB
initial-access
CVE-2017-9841CRITICALbajo ataque14 sep 2020
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware14 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC179
Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.
CVE-2020-1472MEDIUMbajo ataqueransomware14 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC38
cube0x0/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware14 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware14 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-1472MEDIUMbajo ataqueransomware14 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware14 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC397
Exploit Code for CVE-2020-1472 aka Zerologon
CVE-2020-1472MEDIUMbajo ataqueransomware14 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1316
PoC for Zerologon - all research credits go to Tom Tervoort of Secura
CVE-2020-1472MEDIUMbajo ataqueransomware14 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC705
Exploit for zerologon cve-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware14 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-21307HIGH13 sep 2020
Remote Code Exploit in Lucee Admin
78RIESGO
abrir
GitHub PoC7
CVE-2019-15107 exploit
CVE-2019-15107CRITICALbajo ataqueransomware13 sep 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-5902CRITICALbajo ataqueransomware13 sep 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-15505CRITICALbajo ataque13 sep 2020
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1,
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware13 sep 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-26084CRITICALbajo ataqueransomware13 sep 2020
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an un
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2021-22986CRITICALbajo ataqueransomware13 sep 2020
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RIESGO
abrir
GitHub PoC
primebeast/CVE-2019-11932
CVE-2019-1193212 sep 2020
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version
35RIESGO
abrir
Metasploit600
MobileIron MDM Hessian-Based Java Deserialization RCE
CVE-2020-15505CRITICALbajo ataque12 sep 2020
A remote code execution vulnerability in MobileIron Core & Connector versions 10.3.0.3 and earlier, 10.4.0.0, 10.4.0.1,
100RIESGO
abrir
VulnCheck XDB
local
CVE-2015-363611 sep 2020
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque11 sep 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALbajo ataque11 sep 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
local
CVE-2014-6271CRITICALbajo ataque11 sep 2020
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RIESGO
abrir
VulnCheck XDB
local
CVE-2015-754711 sep 2020
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RIESGO
abrir
GitHub PoC
1337in/CVE-2020-3187
CVE-2020-3187CRITICAL11 sep 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Path Traversal Vulnerability
85RIESGO
abrir
Exploit-DBVexDay Proof
CuteNews 2.1.2 - Remote Code Execution
CVE-2019-11447webappsphp10 sep 2020
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload proce
35RIESGO
abrir
Exploit-DB
ZTE Router F602W - Captcha Bypass
CVE-2020-6862webappshardware10 sep 2020
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability. Unauthorized users could lo
23RIESGO
abrir
GitHub PoC2
Automatically exploit systems with vulnerable davfs2 (CVE-2013-4362)
CVE-2013-436210 sep 2020
WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1
23RIESGO
abrir
Metasploit600
Palo Alto Networks Authenticated Remote Code Execution
CVE-2020-2038HIGH09 sep 2020
PAN-OS: OS command injection vulnerability in the management web interface
78RIESGO
abrir
Metasploit300
WordPress File Manager Unauthenticated Remote Code Execution
CVE-2020-25213CRITICALbajo ataque09 sep 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
anteriorpágina 733 / 2612siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.