Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
78.958 exploits
VulnCheck XDB
initial-access
CVE-2019-15107CRITICALbajo ataqueransomware07 oct 2020
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnera
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12615HIGHbajo ataqueransomware07 oct 2020
When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisati
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-3088CRITICALbajo ataque06 oct 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-999506 oct 2020
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RIESGO
abrir
Exploit-DB
SpamTitan 7.07 - Unauthenticated Remote Code Execution
CVE-2020-11698webappsphp05 oct 2020
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware05 oct 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-10271HIGHbajo ataqueransomware05 oct 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security). Supporte
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALbajo ataque05 oct 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-2628CRITICALbajo ataque05 oct 2020
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware04 oct 2020
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware04 oct 2020
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2017-12149CRITICALbajo ataqueransomware04 oct 2020
In Jboss Application Server as shipped with Red Hat Enterprise Application Platform 5.2, it was found that the doFilter
100RIESGO
abrir
Metasploit300
SAP Solution Manager remote unauthorized OS commands execution
CVE-2020-6207CRITICALbajo ataque03 oct 2020
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RIESGO
abrir
Metasploit300
SAP Solution Manager remote unauthorized OS commands execution
CVE-2020-6207CRITICALbajo ataque03 oct 2020
SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform an
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2018-239202 oct 2020
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML Exter
50RIESGO
abrir
GitHub PoC2
coldfusion exploit based on https://cvedetails.com/cve/CVE-2009-2265/
CVE-2009-226502 oct 2020
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RIESGO
abrir
GitHub PoC2
Protect your domain controllers against Zerologon (CVE-2020-1472).
CVE-2020-1472MEDIUMbajo ataqueransomware30 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC5
CVE-2019-18935
CVE-2019-18935CRITICALbajo ataqueransomware30 sep 2020
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUp
100RIESGO
abrir
GitHub PoC
Ken-Abruzzi/CVE-2020-0674
CVE-2020-0674HIGHbajo ataque30 sep 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware30 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2020-0674HIGHbajo ataque30 sep 2020
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
GitHub PoC
Ken-Abruzzi/cve-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware30 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC11
POC for checking multiple hosts for Zerologon vulnerability
CVE-2020-1472MEDIUMbajo ataqueransomware29 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware29 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-1472MEDIUMbajo ataqueransomware29 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
GitHub PoC22
Zerologon AutoExploit Tool | CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware29 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
MSI Ambient Link Driver 1.0.0.8 - Local Privilege Escalation
CVE-2020-17382localwindows28 sep 2020
The MSI AmbientLink MsIo64 driver 1.0.0.8 has a Buffer Overflow (0x80102040, 0x80102044, 0x80102050,and 0x80102054).
23RIESGO
abrir
GitHub PoC
Fa1c0n35/CVE-2020-1472-02-
CVE-2020-1472MEDIUMbajo ataqueransomware28 sep 2020
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Exploit-DB
Mida eFramework 2.8.9 - Remote Code Execution
CVE-2020-15922webappshardware28 sep 2020
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)
35RIESGO
abrir
GitHub PoC3
To crash Windows-10 easily
CVE-2020-0796CRITICALbajo ataqueransomware28 sep 2020
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol h
100RIESGO
abrir
anteriorpágina 746 / 2632siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.