Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
78.958 exploits
Exploit-DB
Apache OpenMeetings 5.0.0 - 'hostname' Denial of Service
CVE-2020-13951webappsmultiple24 nov 2020
Attackers can use public NetTest web service of Apache OpenMeetings 4.0.0-5.0.0 to organize denial of service attack.
45RIESGO
abrir
Exploit-DBVexDay Proof
ZeroShell 3.9.0 - 'cgi-bin/kerbynet' Remote Root Command Injection (Metasploit)
CVE-2019-12725webappslinux24 nov 2020
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web ap
60RIESGO
abrir
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP
CVE-2018-8174HIGHbajo ataqueransomware24 nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC1
www201001/https-github.com-iBearcat-CVE-2018-8174_EXP.git-
CVE-2018-8174HIGHbajo ataqueransomware24 nov 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
Exploit-DB
LifeRay 7.2.1 GA2 - Stored XSS
CVE-2020-7934webappsmultiple23 nov 2020
In LifeRay Portal CE 7.1.0 through 7.2.1 GA2, the First Name, Middle Name, and Last Name fields for user accounts in MyA
23RIESGO
abrir
Exploit-DB
TP-Link TL-WA855RE V5_200415 - Device Reset Auth Bypass
CVE-2020-24363HIGHbajo ataquewebappshardware23 nov 2020
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP
76RIESGO
abrir
GitHub PoC
1stPeak/CVE-2018-15473
CVE-2018-15473MEDIUM23 nov 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC1
This container was made to explain and demonstrate how CVE-2019-15813 (Sentrifugo works)
CVE-2019-1581322 nov 2020
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arb
35RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-0708CRITICALbajo ataqueransomware22 nov 2020
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unau
100RIESGO
abrir
Metasploit600
qdPM 9.1 Authenticated Arbitrary PHP File Upload (RCE)
CVE-2020-724621 nov 2020
A remote code execution (RCE) vulnerability exists in qdPM 9.1 and earlier. An attacker can upload a malicious PHP code
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2019-11043HIGHbajo ataqueransomware21 nov 2020
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1394221 nov 2020
Remote Code Execution in Apache Unomi
50RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1394220 nov 2020
Remote Code Execution in Apache Unomi
50RIESGO
abrir
GitHub PoC2
MasterSploit/LPE---CVE-2020-0796
CVE-2020-0796CRITICALbajo ataqueransomware20 nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALbajo ataqueransomware20 nov 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
GitHub PoC6
FortiVuln
CVE-2018-13379CRITICALbajo ataqueransomware19 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
Exploit-DB
Gemtek WVRTM-127ACN 01.01.02.141 - Authenticated Arbitrary Command Injection
CVE-2020-24365webappscgi19 nov 2020
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic n
28RIESGO
abrir
Metasploit0
Google Chrome versions before 87.0.4280.88 integer overflow during SimplfiedLowering phase
CVE-2020-1604019 nov 2020
Insufficient data validation in V8 in Google Chrome prior to 87.0.4280.88 allowed a remote attacker to potentially explo
60RIESGO
abrir
Exploit-DB
xuucms 3 - 'keywords' SQL Injection
CVE-2020-28091webappsmultiple19 nov 2020
cxuucms v3 has a SQL injection vulnerability, which can lead to the leakage of all database data via the keywords parame
23RIESGO
abrir
Exploit-DB
PESCMS TEAM 2.3.2 - Multiple Reflected XSS
CVE-2020-28092webappsmultiple19 nov 2020
PESCMS Team 2.3.2 has multiple reflected XSS via the id parameter:?g=Team&m=Task&a=my&status=3&id=,?g=Team&m=Task&a=my&s
23RIESGO
abrir
Exploit-DB
Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification
CVE-2018-13382CRITICALbajo ataqueransomwarewebappshardware19 nov 2020
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and Forti
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-13379CRITICALbajo ataqueransomware19 nov 2020
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
GitHub PoC4
CVE-2020-3452
CVE-2020-3452HIGHbajo ataque18 nov 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC2
CVE-2017-10271
CVE-2017-10271HIGHbajo ataqueransomware18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHbajo ataque18 nov 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
Exploit-DB
BigBlueButton 2.2.25 - Arbitrary File Disclosure and Server-Side Request Forgery
CVE-2020-25820webappsmultiple18 nov 2020
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploade
28RIESGO
abrir
Exploit-DB
ZeroLogon - Netlogon Elevation of Privilege
CVE-2020-1472MEDIUMbajo ataqueransomwareremotewindows18 nov 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC10
CVE-2017-3506
CVE-2017-3506HIGHbajo ataque18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supporte
100RIESGO
abrir
GitHub PoC4
PHP-FPM Remote Command Execution Exploit
CVE-2019-11043HIGHbajo ataqueransomware18 nov 2020
Underflow in PHP-FPM can lead to RCE
100RIESGO
abrir
anteriorpágina 738 / 2632siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.