Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
78.958 exploits
Metasploit600
OpenTSDB 2.4.0 unauthenticated command injection
CVE-2020-3547618 nov 2020
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. Th
60RIESGO
abrir
Metasploit0
Firefox MCallGetProperty Write Side Effects Use After Free Exploit
CVE-2020-2695018 nov 2020
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable
30RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware18 nov 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-820917 nov 2020
Improper access control in Citrix XenMobile Server 10.12 before RP2, Citrix XenMobile Server 10.11 before RP4, Citrix Xe
50RIESGO
abrir
Metasploit600
PEAR Archive_Tar 1.4.10 Arbitrary File Write
CVE-2020-28949HIGHbajo ataque17 nov 2020
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper
100RIESGO
abrir
GitHub PoC
windows.vm
CVE-2019-3396CRITICALbajo ataqueransomware17 nov 2020
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from vers
100RIESGO
abrir
GitHub PoC
BabyTeam1024/CVE-2020-14882
CVE-2020-14882CRITICALbajo ataque17 nov 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-1721517 nov 2020
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RIESGO
abrir
GitHub PoC9
A Remote Code Execution (RCE) exploit for Huawei HG532d based on CVE-2017-17215 vulnerability. Modded from original PoC code from exploit-db.com
CVE-2017-1721517 nov 2020
Huawei HG532 with some customized versions has a remote code execution vulnerability. An authenticated attacker could se
45RIESGO
abrir
Exploit-DB
Microsoft Internet Explorer 11 - Use-After-Free
CVE-2020-0674HIGHbajo ataquelocalwindows17 nov 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
GitHub PoC
DHCP exploitation with DynoRoot (CVE-2018-1111)
CVE-2018-1111HIGH17 nov 2020
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
78RIESGO
abrir
Exploit-DB
Apache Struts 2.5.20 - Double OGNL evaluation
CVE-2019-0230remotemultiple17 nov 2020
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir
Exploit-DB
Aerospike Database 5.1.0.3 - OS Command Execution
CVE-2020-13151remotemultiple17 nov 2020
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RIESGO
abrir
GitHub PoC1
b1ack0wl/CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware16 nov 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Metasploit600
Monitorr unauthenticated Remote Code Execution (RCE)
CVE-2020-2887116 nov 2020
Remote code execution in Monitorr v1.7.6m in upload.php allows an unauthorized person to execute arbitrary code on the s
40RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware16 nov 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC1
nex1less/CVE-2015-4852
CVE-2015-4852CRITICALbajo ataque16 nov 2020
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2015-4852CRITICALbajo ataque16 nov 2020
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-15227HIGH15 nov 2020
Remote Code Execution vulnerability
68RIESGO
abrir
Metasploit600
WordPress AIT CSV Import Export Unauthenticated Remote Code Execution
CVE-2020-36849CRITICAL14 nov 2020
AIT CSV import/export <= 3.0.3 - Unauthenticated Arbitrary File Upload
43RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2018-15133HIGHbajo ataque13 nov 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC1
CVE-2020-25213 Wordpress File Manager 6.7 Plugin 0day exploit
CVE-2020-25213CRITICALbajo ataque13 nov 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
Exploit-DB
OpenCart Theme Journal 3.1.0 - Sensitive Data Exposure
CVE-2020-15478webappsphp13 nov 2020
The Journal theme before 3.1.0 for OpenCart allows exposure of sensitive data via SQL errors.
23RIESGO
abrir
Exploit-DB
October CMS Build 465 - Arbitrary File Read Exploit (Authenticated)
CVE-2020-5295MEDIUMwebappsphp13 nov 2020
Local File read vulnerability in OctoberCMS
33RIESGO
abrir
Exploit-DBVexDay Proof
Apache Tomcat - AJP 'Ghostcat' File Read/Inclusion (Metasploit)
CVE-2020-1938CRITICALbajo ataquewebappsmultiple13 nov 2020
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomc
100RIESGO
abrir
Exploit-DB
Touchbase.io 1.10 - Stored Cross Site Scripting
CVE-2020-26218HIGHwebappsmultiple13 nov 2020
HTML Injection in touchbase.ai
41RIESGO
abrir
GitHub PoC12
Hikvision IP camera access bypass exploit, developed by golang.
CVE-2017-7921CRITICALbajo ataque13 nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2017-7921CRITICALbajo ataque13 nov 2020
An Improper Authentication issue was discovered in Hikvision DS-2CD2xx2F-I Series V5.2.0 build 140721 to V5.4.0 build 16
100RIESGO
abrir
GitHub PoC57
Exploit for Laravel Remote Code Execution with API_KEY (CVE-2018-15133)
CVE-2018-15133HIGHbajo ataque13 nov 2020
In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unseri
100RIESGO
abrir
GitHub PoC
rvermeulen/apache-struts-cve-2017-9805
CVE-2017-9805HIGHbajo ataque13 nov 2020
The REST Plugin in Apache Struts 2.1.1 through 2.3.x before 2.3.34 and 2.5.x before 2.5.13 uses an XStreamHandler with a
100RIESGO
abrir
anteriorpágina 739 / 2632siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.