Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
78.958 exploits
Exploit-DB
Seat Reservation System 1.0 - Unauthenticated SQL Injection
CVE-2020-25762webappsphp16 oct 2020
An issue was discovered in SourceCodester Seat Reservation System 1.0. The file admin_class.php does not perform input v
28RIESGO
abrir
GitHub PoC3
CVE-2019–15107 - Unauthenticated RCE Webmin <=1.920
CVE-2019-15107CRITICALbajo ataqueransomware15 oct 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware15 oct 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
GitHub PoC
Check for events that indicate non compatible devices -> CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware15 oct 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-2883CRITICALbajo ataque14 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
GitHub PoC2
FancyDoesSecurity/CVE-2020-2883
CVE-2020-2883CRITICALbajo ataque14 oct 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-5902CRITICALbajo ataqueransomware14 oct 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHbajo ataque14 oct 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
Metasploit600
Microsoft SharePoint Server-Side Include and ViewState RCE
CVE-2020-16952HIGH13 oct 2020
Microsoft SharePoint Remote Code Execution Vulnerability
58RIESGO
abrir
Exploit-DB
Cisco ASA and FTD 9.6.4.42 - Path Traversal
CVE-2020-3452HIGHbajo ataquewebappshardware12 oct 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC10
BlueBorne Exploits & Framework This repository contains a PoC code of various exploits for the BlueBorne vulnerabilities. Under 'android' exploits for the Android RCE vulnerability (CVE-2017-0781), and the SDP Information leak vulnerability (CVE-2017-0785) can be found. Under 'linux-bluez' exploits for the Linux-RCE vulnerability (CVE-2017-1000251) can be found (for Amazon Echo, and Samsung Gear S3). Under 'l2cap_infra' a general testing framework to send and receive raw l2cap messages (using scapy) can be found. Under 'nRF24_BDADDR_Sniffer' a tool to capture bluetooth mac addresses (BDADDR) over the air, using a nRF24L01 chip For more details on BlueBorne, you may read the full technical white paper available here: https://www.armis.com/blueborne/ In addition a several detailed blog posts on the exploitation of these vulnerability can be found here: https://www.armis.com/blog/ =============== Dependencies:
CVE-2017-078112 oct 2020
A remote code execution vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1
28RIESGO
abrir
GitHub PoC4
n3m1sys/CVE-2018-16763-Exploit-Python3
CVE-2018-1676310 oct 2020
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This ca
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-15227HIGH10 oct 2020
Remote Code Execution vulnerability
68RIESGO
abrir
GitHub PoC58
https://medium.com/@mansoorr/exploiting-cve-2020-25213-wp-file-manager-wordpress-plugin-6-9-3f79241f0cd8
CVE-2020-25213CRITICALbajo ataque10 oct 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
VulnCheck XDB
local
CVE-2020-0796CRITICALbajo ataqueransomware10 oct 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware10 oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware10 oct 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-25213CRITICALbajo ataque10 oct 2020
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitra
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware10 oct 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC2
shanfenglan/cve-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware10 oct 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC2
提供单个或批量URL扫描是否存在CVE-2022-22954功能
CVE-2022-22954CRITICALbajo ataqueransomware09 oct 2020
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side templa
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-0688HIGHbajo ataqueransomware09 oct 2020
A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle o
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-15227HIGH09 oct 2020
Remote Code Execution vulnerability
68RIESGO
abrir
GitHub PoC5
Typesetter CMS文件上传漏洞环境
CVE-2020-2579009 oct 2020
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RIESGO
abrir
Exploit-DB
Kentico CMS 9.0-12.0.49 - Persistent Cross Site Scripting
CVE-2019-19493webappsphp09 oct 2020
Kentico before 12.0.50 allows file uploads in which the Content-Type header is inconsistent with the file extension, lea
23RIESGO
abrir
Exploit-DB
D-Link DSR-250N 3.12 - Denial of Service (PoC)
CVE-2020-26567webappshardware08 oct 2020
An issue was discovered on D-Link DSR-250N before 3.17B devices. The CGI script upgradeStatusReboot.cgi can be accessed
28RIESGO
abrir
GitHub PoC
Bludit 3.9.2 - Remote command execution - CVE-2019-16113
CVE-2019-1611307 oct 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
Metasploit600
Gogs Git Hooks Remote Code Execution
CVE-2020-1586707 oct 2020
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privile
40RIESGO
abrir
Metasploit600
Gitea Git Hooks Remote Code Execution
CVE-2020-1414407 oct 2020
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer envir
40RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware07 oct 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
anteriorpágina 745 / 2632siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.