Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
79.057 exploits
GitHub PoC2
unauth file read in cisco asa & firepower.
CVE-2020-3452HIGHbajo ataque24 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
VulnCheck XDB
infoleak
CVE-2020-3452HIGHbajo ataque24 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
GitHub PoC2
XDev05/CVE-2020-3452-PoC
CVE-2020-3452HIGHbajo ataque24 jul 2020
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Read-Only Path Traversal Vulnerability
100RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-11826HIGHbajo ataque23 jul 2020
Microsoft Office 2010, SharePoint Enterprise Server 2010, SharePoint Server 2010, Web Applications, Office Web Apps Serv
93RIESGO
abrir
VulnCheck XDB
client-side
CVE-2017-8759HIGHbajo ataque23 jul 2020
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-2555CRITICALbajo ataque22 jul 2020
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Su
100RIESGO
abrir
Exploit-DB
Docsify.js 4.11.4 - Reflective Cross-Site Scripting
CVE-2020-7680webappsmultiple22 jul 2020
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a
23RIESGO
abrir
Exploit-DB
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
CVE-2020-15363webappsphp22 jul 2020
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
23RIESGO
abrir
Exploit-DB
WordPress Theme NexosReal Estate 1.7 - 'search_order' SQL Injection
CVE-2020-15364webappsphp22 jul 2020
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
23RIESGO
abrir
GitHub PoC2
sap netweaver portal add user administrator
CVE-2020-6287CRITICALbajo ataque22 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
GitHub PoC
A powershell script to deploy the registry mitigation key for CVE-2020-1350
CVE-2020-1350CRITICALbajo ataque22 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC28
Onapsis/CVE-2020-6287_RECON-scanner
CVE-2020-6287CRITICALbajo ataque21 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-6287CRITICALbajo ataque21 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
GitHub PoC1
Ported Exploit From Python To Golang
CVE-2018-689220 jul 2020
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2020-6287CRITICALbajo ataque20 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
GitHub PoC96
PoC for CVE-2020-6287 The PoC in python for add user only, no administrator permission set. Inspired by @zeroSteiner from metasploit. Original Metasploit PR module: https://github.com/rapid7/metasploit-framework/pull/13852/commits/d1e2c75b3eafa7f62a6aba9fbe6220c8da97baa8 This PoC only create user with unauthentication permission and no more administrator permission set. This project is created only for educational purposes and cannot be used for law violation or personal gain. The author of this project is not responsible for any possible harm caused by the materials of this project. Original finding: CVE-2020-6287: Pablo Artuso CVE-2020-6286: Yvan 'iggy' G. Usage: python sap-CVE-2020-6287-add-user.py <HTTP(s)://IP:Port
CVE-2020-6287CRITICALbajo ataque20 jul 2020
SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication c
100RIESGO
abrir
GitHub PoC3
DaBoQuan/CVE-2020-14645
CVE-2020-14645CRITICAL20 jul 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RIESGO
abrir
GitHub PoC17
f5devcentral/cve-2020-5902-ioc-bigip-checker
CVE-2020-5902CRITICALbajo ataqueransomware20 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC80
Weblogic CVE-2020-14645 UniversalExtractor JNDI injection getDatabaseMetaData()
CVE-2020-14645CRITICAL20 jul 2020
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions th
60RIESGO
abrir
Metasploit400
Moodle Teacher Enrollment Privilege Escalation to RCE
CVE-2020-1432120 jul 2020
In Moodle before 3.9.1, 3.8.4, 3.7.7 and 3.5.13, teachers of a course were able to assign themselves the manager role wi
23RIESGO
abrir
GitHub PoC
DNS Vulnerability - CVE-2020-1350
CVE-2020-1350CRITICALbajo ataque19 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC4
Iamgublin/CVE-2020-1054
CVE-2020-1054HIGHbajo ataque19 jul 2020
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
GitHub PoC2
Scanner and Mitigator for CVE 2020-1350
CVE-2020-1350CRITICALbajo ataque18 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC4
Enviroment and exploit to rce test
CVE-2020-816318 jul 2020
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the
60RIESGO
abrir
GitHub PoC11
CVE-2020-1350 Proof-of-Concept
CVE-2020-1350CRITICALbajo ataque17 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
GitHub PoC8
GUI
CVE-2020-5902CRITICALbajo ataqueransomware17 jul 2020
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
GitHub PoC
Bludit Exploitation Via upload Image.php
CVE-2019-1611317 jul 2020
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
GitHub PoC10
Citrix Unauthorized Remote Code Execution Attacker - CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware17 jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
VulnCheck XDB
initial-access
CVE-2019-19781CRITICALbajo ataqueransomware17 jul 2020
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
VulnCheck XDB
denial-of-service
CVE-2020-1350CRITICALbajo ataque17 jul 2020
A remote code execution vulnerability exists in Windows Domain Name System servers when they fail to properly handle req
100RIESGO
abrir
anteriorpágina 759 / 2636siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.