Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.039exploits catalogados
36.284CVEs con explotación pública
24.695probados en laboratorio
79.041 exploits
GitHub PoC1
Educational standalone JavaScript implementation of the public exploit for CVE-2016-9079 (Firefox Use-After-Free), adapted from the original Exploit-DB/Metasploit module.
CVE-2016-9079HIGHbajo ataque06 ago 2020
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
GitHub PoC
CVE-2013-3214
CVE-2013-321406 ago 2020
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
60RIESGO
abrir
VulnCheck XDB
client-side
CVE-2018-20250HIGHbajo ataqueransomware06 ago 2020
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field o
100RIESGO
abrir
GitHub PoC6
Pi-hole ( <= 4.3.2) authenticated remote code execution.
CVE-2020-8816CRITICALbajo ataque06 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-8816CRITICALbajo ataque06 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2016-9079HIGHbajo ataque06 ago 2020
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
Exploit-DB
ACTi NVR3 Standard or Professional Server 3.0.12.42 - Denial of Service (PoC)
CVE-2020-15956doswindows05 ago 2020
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer
28RIESGO
abrir
GitHub PoC5
This was converted from a metasploit module as an exercise for OSCP studying
CVE-2012-298205 ago 2020
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RIESGO
abrir
Metasploit600
Cisco AnyConnect Privilege Escalations (CVE-2020-3153 and CVE-2020-3433)
CVE-2020-3433HIGHbajo ataqueransomware05 ago 2020
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
91RIESGO
abrir
Metasploit600
Cisco AnyConnect Privilege Escalations (CVE-2020-3153 and CVE-2020-3433)
CVE-2020-3153MEDIUMbajo ataqueransomware05 ago 2020
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
83RIESGO
abrir
GitHub PoC11
Pi-hole Remote Code Execution authenticated Version >= 4.3.2
CVE-2020-8816CRITICALbajo ataque04 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2020-8816CRITICALbajo ataque04 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
GitHub PoC2
Solr_CVE-2019-17558
CVE-2019-17558HIGHbajo ataque04 ago 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-17558HIGHbajo ataque04 ago 2020
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir
GitHub PoC5
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer overflow and application termination via a malformed payload.
CVE-2020-1595604 ago 2020
ActiveMediaServer.exe in ACTi NVR3 Standard Server 3.0.12.42 allows remote unauthenticated attackers to trigger a buffer
28RIESGO
abrir
Exploit-DB
Pi-hole 4.3.2 - Remote Code Execution (Authenticated)
CVE-2020-8816CRITICALbajo ataquewebappspython04 ago 2020
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHbajo ataque03 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC
Checks a list of SSH servers for password-based auth availability and for the existence of SSH user enumeration vulnerability (CVE-2018-15473) in those identified.
CVE-2018-15473MEDIUM03 ago 2020
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC1
CVE-2020-3452 - directory traversal in Cisco ASA and Cisco Firepower Threat Defense
CVE-2020-3452HIGHbajo ataque03 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-398003 ago 2020
The Solarwinds Dameware Mini Remote Client agent v12.1.0.89 supports smart card authentication which can allow a user to
23RIESGO
abrir
GitHub PoC24
CVE-2020-3452 exploit
CVE-2020-3452HIGHbajo ataque01 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC
修改IP地址即可实现命令执行
CVE-2017-804601 ago 2020
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHbajo ataque01 ago 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2017-804601 ago 2020
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-1350CRITICALbajo ataque01 ago 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC42
POC for CVE-2020-13151
CVE-2020-1315101 ago 2020
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2016-3088CRITICALbajo ataque31 jul 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2018-8174HIGHbajo ataqueransomware31 jul 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC
ericisnotrealname/CVE-2018-8174_EXP
CVE-2018-8174HIGHbajo ataqueransomware31 jul 2020
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows
93RIESGO
abrir
GitHub PoC15
ActiveMQ_putshell直接获取webshell
CVE-2016-3088CRITICALbajo ataque31 jul 2020
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
anteriorpágina 756 / 2635siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.